CVE-2019-16064Path Traversal in Enigma Network Management Solution

CWE-22Path Traversal3 documents3 sources
Severity
9.6CRITICALNVD
EPSS
1.0%
top 22.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 24

Description

NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerability, it is possible for an attacker to list operating-system directory contents on the server, create directories and upload files in permissible locations, and modify filenames and delete files that are accessible by the user running the web server instance.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NExploitability: 3.1 | Impact: 5.8

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m5c8-4mgp-62q7: NETSAS Enigma NMS 652022-05-24
CVEList
CVE-2019-16064: NETSAS Enigma NMS 652020-03-19
CVE-2019-16064 — Path Traversal | cvebase