CVE-2024-7634: F5 Nginx Agent

Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.

NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

Affected products

  • F5 Nginx Agent: from 2.17.0, before 2.37.0 (fixed in 2.37.0)
  • F5 Nginx Instance Manager: from 2.3.1, before 2.17.2 (fixed in 2.17.2)

Published 2024-08-22. Last modified 2026-06-17.