Impact
The NGINX Agent’s config_dirs directive does not properly validate directory paths, permitting a low‑privileged, remotely authenticated user to read or write files outside the set of directories defined in the Agent configuration. This directory traversal style flaw (CWE‑22) allows the attacker to cross a security boundary and potentially alter or access sensitive files on the host, such as configuration or credential files, without acquiring higher privileges.
Affected Systems
F5’s NGINX Agent and NGINX Instance Manager are impacted. Any release containing the vulnerable config_dirs handling is susceptible; the advisory explicitly references the F5:NGINX Agent and F5:NGINX Instance Manager. Software that has reached end of technical support is not evaluated in this assessment.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, and the EPSS score of less than 1 % indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with a low‑privilege account and to manipulate the config_dirs request to a path outside the permitted directories, resulting in limited read/write access to files beyond the intended boundary.
OpenCVE Enrichment