Record summary

CVE-2019-16072 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 13, 2019 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

enigma_network_management_solution

Browse netsas / enigma_network_management_solution
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBEnigma NMS 65.0.0 - OS Command InjectionExploitDB exploitby xerubusNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALEnigma NMS < 65.0.0 - Authenticated OS Command InjectionCVSS 9.8

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an authenticated attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

Impact

Attackers can execute arbitrary code on the server, potentially leading to full system compromise.

Remediation

Update to the latest version of NETSAS Enigma NMS or apply security patches that fix input sanitization.

WeaknessesCWE-78
Authors0x_Akoko
Template tagscvecve2019authenticatedenigmanmsoastoobvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:netsas:enigma_network_management_solution:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2