CVE-2019-16071: Netsas Enigma Nms

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is possible for a low-privileged user to perform all actions as an administrator by bypassing authorization controls and sending requests to the server in the context of an administrator.

Affected products

  • Netsas Enigma Nms: up to and including 65.0.0

Published 2020-03-20. Last modified 2026-06-17.