CVE-2019-16066

HIGH

NETSAS Enigma NMS <65.0.0 - Code Injection

Title source: llm
STIX 2.1

Description

An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attacker to upload malicious files and perform arbitrary code execution on the system.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.mogozobo.com/?p=3647

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 60.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
netsas/enigma_network_management_solution < 65.0.0
Published Mar 19, 2020
Tracked Since Feb 18, 2026