Vulnerabilities (CVE)

Filtered by vendor Netsas Subscribe
Filtered by product Enigma Network Management Solution
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16072 1 Netsas 1 Enigma Network Management Solution 2020-03-24 10.0 HIGH 9.8 CRITICAL
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
CVE-2019-16064 1 Netsas 1 Enigma Network Management Solution 2020-03-23 5.5 MEDIUM 9.6 CRITICAL
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerability, it is possible for an attacker to list operating-system directory contents on the server, create directories and upload files in permissible locations, and modify filenames and delete files that are accessible by the user running the web server instance.