CVE-2019-16067
Summary
| CVE | CVE-2019-16067 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-19 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to steal username and password combinations by intercepting authentication traffic in transit. |
Risk And Classification
Problem Types: CWE-319 | CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netsas | Enigma Network Management Solution | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mogozobo » (CVE-2019-16061 –> CVE-2019-16072) Enigma NMS Multiple Vulnerabilities | MISC | www.mogozobo.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.