CVE-2019-16072
netsas enigma_network_management_solution Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2019-16072 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
enigma_network_management_solutionBrowse netsas / enigma_network_management_solution | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBEnigma NMS 65.0.0 - OS Command InjectionExploitDB exploitby xerubusNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALEnigma NMS < 65.0.0 - Authenticated OS Command InjectionCVSS 9.8
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an authenticated attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
Impact
Attackers can execute arbitrary code on the server, potentially leading to full system compromise.
Remediation
Update to the latest version of NETSAS Enigma NMS or apply security patches that fix input sanitization.
Source: ProjectDiscovery