Skip to content
Noroxi

netsas records

12 published records for vendor netsas.

All records

12 records
  • An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to exec

    CriticalCVSS 9.8Proof of conceptEPSS 26%

    netsas · enigma network management solutionMar 19, 2020

  • NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and

    CriticalCVSS 9.6No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execut

    HighCVSS 8.8Proof of conceptEPSS 3%

    netsas · enigma network management solutionMar 19, 2020

  • An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior.

    HighCVSS 8.8No exploitEPSS 2%

    netsas · enigma network management solutionMar 19, 2020

  • Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any setting

    HighCVSS 8.8No exploitEPSS 1%

    netsas · enigma nmsMar 19, 2020

  • A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing

    HighCVSS 8.8No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into sub

    HighCVSS 8.8Proof of conceptEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application.

    HighCVSS 7.5No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages.

    HighCVSS 7.5No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database.

    MediumCVSS 6.5No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa

    MediumCVSS 6.1No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020

  • A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa

    MediumCVSS 6.1No exploitEPSS 1%

    netsas · enigma network management solutionMar 19, 2020