CVE detail
CVE-2020-5895 — CVE-2020-5895
Published 2020-05-07 · Modified 2026-06-17 · Vendor f5 · Product nginx_controller · Source nvd
HIGH
severity
CVSS-derived band
0.0030
EPSS probability
exploitation probability, 30d
23.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on the local system to write arbitrary data into the socket. A local system attacker can make AVRD segmentation fault (SIGSEGV) by writing malformed messages to the socket.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References