PT-2020-9778 · Netsas · Netsas Enigma Nms

Published

2020-03-19

·

Updated

2021-07-21

·

CVE-2019-16062

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NETSAS Enigma NMS versions 65.0.0 and prior
Description The issue concerns the lack of encryption for sensitive data stored within the SQL database. This allows an attacker to potentially expose unencrypted sensitive data.
Recommendations For versions 65.0.0 and prior, consider implementing encryption for sensitive data stored in the SQL database as a mitigation measure. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16062

Affected Products

Netsas Enigma Nms