PT-2020-9783 · Netsas · Netsas Enigma Nms

Published

2020-03-19

·

Updated

2021-07-21

·

CVE-2019-16067

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NETSAS Enigma NMS versions 65.0.0 and prior
Description The issue concerns the use of basic authentication over HTTP for access control to the web application, which can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit. This is due to the use of weak authentication transmitted over cleartext protocols.
Recommendations For NETSAS Enigma NMS versions 65.0.0 and prior, consider disabling the use of basic authentication over HTTP until a more secure authentication method is implemented. Restrict access to the web application to minimize the risk of exploitation. Avoid using cleartext protocols for transmitting sensitive information, such as username and password combinations.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16067

Affected Products

Netsas Enigma Nms