CVE-2019-16067Cleartext Transmission of Sensitive Info in Enigma Network Management Solution

Severity
7.5HIGHNVD
EPSS
0.2%
top 64.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 24

Description

NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-272x-qj5p-5hgv: NETSAS Enigma NMS 652022-05-24
CVEList
CVE-2019-16067: NETSAS Enigma NMS 652020-03-19
CVE-2019-16067 — HIGH severity | cvebase