RULE(RULE ID:330128)

Rule General Information
Release Date: 2019-12-16
Rule Name: Enigma Network Management Systems v65.0.0 Code Injection Vulnerability (CVE-2019-16072)
Severity:
CVE ID:
Rule Protection Details
Description: An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
Impact: An attacker could use this vulnerability to execute arbitrary code.
Affected OS: Linux
Reference: https://www.mogozobo.com/?p=3647
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.netsas.com.au/