Description
A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g., .htpasswd) and create/modify/delete content (e.g., under /var/www/html/docs) within the operating system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6923 | A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g., .htpasswd) and create/modify/delete content (e.g., under /var/www/html/docs) within the operating system. |
References
| Link | Providers |
|---|---|
| https://www.mogozobo.com/?p=3647 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:03:32.669Z
Reserved: 2019-09-06T00:00:00.000Z
Link: CVE-2019-16061
No data.
Status : Modified
Published: 2020-03-19T18:15:13.913
Modified: 2024-11-21T04:29:58.717
Link: CVE-2019-16061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD