Products: 2
    Vulnerabilities: 12
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-16071

    Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is possible for a low-privileged user to perform all actions as an administrator by bypassing authorization controls and sending requests to the server in the context of an administrator.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2020

    CVE-2019-16072

    An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2020

    CVE-2019-16069

    A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through the SNMP protocol.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2020

    CVE-2019-16068

    A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2020

    CVE-2019-16063

    NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted sensitive data.

    Last Modified: Nov 21, 2024
    Published: Mar 19, 2020
    Items Per Page
    Netsas Vulnerabilities & Security CVEs | CVE-DB