Skip to content
COOEY

EXPOSURES › CVE-2019-16278

CVE-2019-16278

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-16278 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Nostromo's nhttpd shipped with a remote code execution vulnerability in http_verify() that allows attackers to traverse directories and execute arbitrary code.

This unpatched directory traversal flaw in nhttpd enables remote code execution, posing a severe risk to DIB systems relying on Nostromo's web server components. The vulnerability is actively exploited in the wild and allows attackers to bypass security controls, potentially compromising sensitive data or enabling lateral movement within a network. DIB organizations must immediately audit their deployments of nhttpd and apply vendor patches or replace the component to prevent exploitation.

Shame score — A critical RCE vulnerability in a web server component that is actively exploited in the wild indicates a severe failure in vendor security practices and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.