PT-2020-9782 · Netsas · Netsas Enigma Nms
Published
2020-03-19
·
Updated
2020-03-23
·
CVE-2019-16066
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NETSAS Enigma NMS versions 65.0.0 and prior
Description
An unrestricted file upload vulnerability exists in user and system file upload functions. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
Recommendations
For NETSAS Enigma NMS versions 65.0.0 and prior, consider restricting access to the file upload functions as a temporary workaround until a patch is available. Restricting the types of files that can be uploaded can also help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netsas Enigma Nms