← Vulnerability feed

Vulnerability record · CVE-2019-16072 · published 20 March 2020

CVE-2019-16072: Netsas enigma network management solution os command injection vulnerability

NNetsas · Enigma Network Management Solution

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

9.8 CVSS 3.1 Critical EPSS 26% · top 2.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.mogozobo.com/?p=3647 ExploitThird Party Advisory
https://www.mogozobo.com/?p=3647 ExploitThird Party Advisory

Track CVE-2019-16072 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2019-16064Netsas enigma network management solution path traversal vulnerabilityNETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and director…EPSS 1.3%8.8CVE-2019-16068Netsas enigma network management solution cross-site scripting vulnerabilityA CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a…EPSS 0.95%8.8CVE-2019-16065Netsas enigma network management solution sql injection vulnerabilityA remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL com…EPSS 2.8%8.8CVE-2019-16066Netsas enigma network management solution unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This allows an attac…EPSS 2.2%8.8CVE-2019-16061Netsas enigma network management solution incorrect default permissions vulnerabilityA number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low p…EPSS 0.99%7.5CVE-2019-16063Netsas enigma network management solution cleartext transmission vulnerabilityNETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an attacker to expose unencrypted se…EPSS 0.67%7.5CVE-2019-16067Netsas enigma network management solution cleartext transmission vulnerabilityNETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authe…EPSS 0.78%6.5CVE-2019-16062Netsas enigma network management solution cleartext storage of sensitive data vulnerabilityNETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypt…EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2019-16072), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.