netsas records
12 published records for vendor netsas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 8.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-276 Incorrect Default Permissions1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2019-16072Proof of concept | An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execnetsas · enigma network management solution · CWE-78 | Critical9.8 | — | 25.9% | Mar 19, 2020 |
38Monitor | CVE-2019-16064No exploit | NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files andnetsas · enigma network management solution · CWE-22 | Critical9.6 | — | 1.3% | Mar 19, 2020 |
36Monitor | CVE-2019-16065Proof of concept | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to executnetsas · enigma network management solution · CWE-89 | High8.8 | — | 2.8% | Mar 19, 2020 |
36Monitor | CVE-2019-16066No exploit | An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior.netsas · enigma network management solution · CWE-434 | High8.8 | — | 2.2% | Mar 19, 2020 |
35Monitor | CVE-2019-16071No exploit | Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settingnetsas · enigma nms · CWE-269 | High8.8 | — | 1.0% | Mar 19, 2020 |
35Monitor | CVE-2019-16061No exploit | A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing netsas · enigma network management solution · CWE-276 | High8.8 | — | 1.0% | Mar 19, 2020 |
35Monitor | CVE-2019-16068Proof of concept | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into subnetsas · enigma network management solution · CWE-79 | High8.8 | — | 0.9% | Mar 19, 2020 |
30Monitor | CVE-2019-16067No exploit | NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application.netsas · enigma network management solution · CWE-319 | High7.5 | — | 0.8% | Mar 19, 2020 |
30Monitor | CVE-2019-16063No exploit | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages.netsas · enigma network management solution · CWE-319 | High7.5 | — | 0.7% | Mar 19, 2020 |
26Monitor | CVE-2019-16062No exploit | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database.netsas · enigma network management solution · CWE-312 | Medium6.5 | — | 0.8% | Mar 19, 2020 |
24Monitor | CVE-2019-16070No exploit | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threanetsas · enigma network management solution · CWE-79 | Medium6.1 | — | 0.7% | Mar 19, 2020 |
24Monitor | CVE-2019-16069No exploit | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threanetsas · enigma network management solution · CWE-79 | Medium6.1 | — | 0.7% | Mar 19, 2020 |
- CVE-2019-1607247Plan
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to exec
CriticalCVSS 9.8Proof of conceptEPSS 26%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606438Monitor
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and
CriticalCVSS 9.6No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606536Monitor
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execut
HighCVSS 8.8Proof of conceptEPSS 3%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606636Monitor
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior.
HighCVSS 8.8No exploitEPSS 2%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1607135Monitor
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any setting
HighCVSS 8.8No exploitEPSS 1%netsas · enigma nmsMar 19, 2020
- CVE-2019-1606135Monitor
A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing
HighCVSS 8.8No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606835Monitor
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into sub
HighCVSS 8.8Proof of conceptEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606730Monitor
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application.
HighCVSS 7.5No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606330Monitor
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages.
HighCVSS 7.5No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606226Monitor
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database.
MediumCVSS 6.5No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1607024Monitor
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa
MediumCVSS 6.1No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020
- CVE-2019-1606924Monitor
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa
MediumCVSS 6.1No exploitEPSS 1%netsas · enigma network management solutionMar 19, 2020