« Volver al listado

CVE-2026-28755

Estado: AnalizadaMedia (5.3)—

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-28755",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-28755",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-24T15:24:10.756255Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f5sirt@f5.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f5sirt@f5.com",
      "affectedData": [
        {
          "vendor": "F5",
          "modules": [
            "ngx_stream_ssl_module"
          ],
          "product": "NGINX Open Source",
          "versions": [
            {
              "status": "affected",
              "version": "1.29.0",
              "lessThan": "1.29.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.27.2",
              "lessThan": "1.28.3",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "F5",
          "modules": [
            "ngx_stream_ssl_module"
          ],
          "product": "NGINX Plus",
          "versions": [
            {
              "status": "affected",
              "version": "R36",
              "lessThan": "R36 P3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R35",
              "lessThan": "R35 P2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R34",
              "lessThan": "*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "R33",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-03-24T15:16:33.773",
  "references": [
    {
      "url": "https://my.f5.com/manage/s/article/K000160368",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "f5sirt@f5.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f5sirt@f5.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
    },
    {
      "lang": "es",
      "value": "NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_stream_ssl_module debido al manejo inadecuado de certificados revocados cuando se configura con las directivas ssl_verify_client on y ssl_ocsp on, permitiendo que el handshake TLS tenga éxito incluso después de que una verificación OCSP identifique el certificado como revocado.\n\nNota: Las versiones de software que han alcanzado el Fin de Soporte Técnico (EoTS) no son evaluadas."
    }
  ],
  "lastModified": "2026-06-17T10:28:59.433",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F58BD02-EA76-4F32-87D6-430026C8553E"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46DC49B8-7286-4867-9CDA-1C1B469CD304"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43477C2E-7485-4146-B25C-F58D632CD85B"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A25B9CF-02C0-42DE-9C70-F2AD3ACE3CEB"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86358605-55F9-4F6F-846A-3F48738F6E05"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7453D683-FCA7-46EE-BE49-5FD9A01D7F87"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A977BF9F-D165-4B93-B4D2-A177883A5E75"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4958360C-7993-4C82-8685-202D4940CE01"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "942CA349-3FF8-4B9D-B87E-FBA8930CE913"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7993A0FB-BE7E-4634-BF7F-FDEE3582D3E7"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "862EA47E-8D57-434E-9C8F-238325FB85B2"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BABB440C-6106-42C6-8E67-101182F26C86",
              "versionEndIncluding": "0.9.7",
              "versionStartIncluding": "0.5.13"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F07D30E-931D-415D-83C6-59F1EC804688",
              "versionEndExcluding": "1.28.3",
              "versionStartIncluding": "1.27.2"
            },
            {
              "criteria": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0EFE28B-E8E5-464E-B407-96436CA87C8E",
              "versionEndExcluding": "1.29.7",
              "versionStartIncluding": "1.29.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "f5sirt@f5.com"
}