Vulnerabilities > Netsas > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2019-16072 OS Command Injection vulnerability in Netsas Enigma Network Management Solution
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
network
low complexity
netsas CWE-78
critical
9.8
2020-03-19 CVE-2019-16064 Path Traversal vulnerability in Netsas Enigma Network Management Solution
NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder.
network
low complexity
netsas CWE-22
critical
9.6