A critical security vulnerability was identified in NETSAS Enigma Network Management System (NMS) versions prior to 65.0.0, specifically involving an OS command injection flaw in the discover_and_manage CGI script. This vulnerability, tracked as CVE-2019-16072, allows authenticated attackers to escalate privileges and execute arbitrary operating system commands on the affected server. The root cause of the issue is improper neutralization of shell metacharacters in the ip_address variable when the snmp_browser action is invoked, enabling attackers to inject malicious commands. Security researchers have provided detailed technical analysis and proof-of-concept exploits, demonstrating how an attacker with valid credentials can leverage this flaw to gain unauthorized control over the system. The vulnerability has been cataloged in the National Vulnerability Database and is referenced in multiple security advisories and exploit databases. In response, detection templates have been developed for automated vulnerability scanning tools, such as ProjectDiscovery's Nuclei, to help organizations identify exposed Enigma NMS instances. These templates facilitate the detection of vulnerable systems by matching specific HTTP response patterns and metadata associated with Enigma NMS deployments. Additional detection configurations have been contributed to open-source repositories, enabling security teams to efficiently locate and assess the risk of this vulnerability within their environments. The community has also provided guidance on using search engines like Shodan and Fofa to discover potentially affected Enigma NMS installations on the internet. Remediation steps include updating Enigma NMS to version 65.0.0 or later, which addresses the command injection flaw. Organizations are urged to review their Enigma NMS deployments, apply available patches, and restrict access to management interfaces to mitigate exploitation risk. The vulnerability is considered significant due to the potential for full system compromise if exploited by a malicious actor. Security professionals recommend continuous monitoring and regular vulnerability assessments to ensure that all instances of Enigma NMS are secured against this and similar threats. The collaborative efforts of the security community have resulted in improved detection and awareness, helping organizations respond proactively to this critical issue. The availability of detection templates and public advisories underscores the importance of timely patching and defense-in-depth strategies for network management systems. This incident highlights the ongoing need for secure coding practices and thorough input validation in web-based management applications. By leveraging community-contributed detection tools and following best practices, organizations can reduce their exposure to privilege escalation and command injection attacks targeting Enigma NMS.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request or issue was created to add a Nuclei template file for CVE-2021-45467, labeled vKEV. The available reference contains workflow activity but no substantive technical details about the vulnerability itself.
A Nuclei pull request was opened to add a template for detecting or validating CVE-2019-16072 in Enigma NMS, describing it as a privilege-escalation OS command injection issue and marking it as KEV-related.
A Nuclei pull request was opened to add detection configuration for Enigma NMS, indicating public security detection work for the product. The reference does not include technical details beyond the addition request.
A privilege-escalation OS command injection vulnerability, tracked as CVE-2019-16072, was identified in Enigma NMS versions earlier than 65.0.0. The reference does not provide the original disclosure date, only that the issue is later treated as known and exploitable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.