PT-2020-9782 · Netsas · Netsas Enigma Nms

Published

2020-03-19

·

Updated

2020-03-23

·

CVE-2019-16066

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NETSAS Enigma NMS versions 65.0.0 and prior
Description An unrestricted file upload vulnerability exists in user and system file upload functions. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.
Recommendations For NETSAS Enigma NMS versions 65.0.0 and prior, consider restricting access to the file upload functions as a temporary workaround until a patch is available. Restricting the types of files that can be uploaded can also help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16066

Affected Products

Netsas Enigma Nms