Записи netsas
12 опубликованных записей вендора netsas.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 8,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-319 Cleartext Transmission of Sensitive Information2
- CWE-276 Incorrect Default Permissions1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2019-16072Proof of concept | An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execnetsas · enigma network management solution · CWE-78 | Критическая9,8 | — | 25,9 % | 19 мар. 2020 г. |
38Наблюдать | CVE-2019-16064Эксплойта нет | NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files andnetsas · enigma network management solution · CWE-22 | Критическая9,6 | — | 1,3 % | 19 мар. 2020 г. |
36Наблюдать | CVE-2019-16065Proof of concept | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to executnetsas · enigma network management solution · CWE-89 | Высокая8,8 | — | 2,8 % | 19 мар. 2020 г. |
36Наблюдать | CVE-2019-16066Эксплойта нет | An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior.netsas · enigma network management solution · CWE-434 | Высокая8,8 | — | 2,2 % | 19 мар. 2020 г. |
35Наблюдать | CVE-2019-16071Эксплойта нет | Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settingnetsas · enigma nms · CWE-269 | Высокая8,8 | — | 1,0 % | 19 мар. 2020 г. |
35Наблюдать | CVE-2019-16061Эксплойта нет | A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing netsas · enigma network management solution · CWE-276 | Высокая8,8 | — | 1,0 % | 19 мар. 2020 г. |
35Наблюдать | CVE-2019-16068Proof of concept | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into subnetsas · enigma network management solution · CWE-79 | Высокая8,8 | — | 0,9 % | 19 мар. 2020 г. |
30Наблюдать | CVE-2019-16067Эксплойта нет | NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application.netsas · enigma network management solution · CWE-319 | Высокая7,5 | — | 0,8 % | 19 мар. 2020 г. |
30Наблюдать | CVE-2019-16063Эксплойта нет | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages.netsas · enigma network management solution · CWE-319 | Высокая7,5 | — | 0,7 % | 19 мар. 2020 г. |
26Наблюдать | CVE-2019-16062Эксплойта нет | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database.netsas · enigma network management solution · CWE-312 | Средняя6,5 | — | 0,8 % | 19 мар. 2020 г. |
24Наблюдать | CVE-2019-16070Эксплойта нет | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threanetsas · enigma network management solution · CWE-79 | Средняя6,1 | — | 0,7 % | 19 мар. 2020 г. |
24Наблюдать | CVE-2019-16069Эксплойта нет | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threanetsas · enigma network management solution · CWE-79 | Средняя6,1 | — | 0,7 % | 19 мар. 2020 г. |
- CVE-2019-1607247В плане
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to exec
КритическаяCVSS 9,8Proof of conceptEPSS 26 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606438Наблюдать
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606536Наблюдать
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execut
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606636Наблюдать
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1607135Наблюдать
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any setting
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %netsas · enigma nms19 мар. 2020 г.
- CVE-2019-1606135Наблюдать
A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606835Наблюдать
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into sub
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606730Наблюдать
NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606330Наблюдать
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606226Наблюдать
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1607024Наблюдать
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa
СредняяCVSS 6,1Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.
- CVE-2019-1606924Наблюдать
A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threa
СредняяCVSS 6,1Эксплойта нетEPSS 1 %netsas · enigma network management solution19 мар. 2020 г.