PT-2020-9783 · Netsas · Netsas Enigma Nms
Published
2020-03-19
·
Updated
2021-07-21
·
CVE-2019-16067
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NETSAS Enigma NMS versions 65.0.0 and prior
Description
The issue concerns the use of basic authentication over HTTP for access control to the web application, which can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit. This is due to the use of weak authentication transmitted over cleartext protocols.
Recommendations
For NETSAS Enigma NMS versions 65.0.0 and prior, consider disabling the use of basic authentication over HTTP until a more secure authentication method is implemented. Restrict access to the web application to minimize the risk of exploitation. Avoid using cleartext protocols for transmitting sensitive information, such as username and password combinations.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netsas Enigma Nms