PT-2020-9780 · Netsas · Netsas Enigma Nms
Published
2020-03-19
·
Updated
2020-03-23
·
CVE-2019-16064
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NETSAS Enigma NMS versions 65.0.0 and prior
Description
The issue allows an authenticated user to access files and directories stored outside of the web root folder due to a directory traversal vulnerability. This can enable an attacker to list operating-system directory contents on the server, create directories and upload files in permissible locations, and modify filenames and delete files that are accessible by the user running the web server instance.
Recommendations
For NETSAS Enigma NMS versions 65.0.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netsas Enigma Nms