Security Advisory

CVE-2024-46257

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-09-27 00:00:00
Last updated 2024-10-24 17:13:28
Assigner mitre
State PUBLISHED

Description

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Lets Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.