Skip to content
COOEY

EXPOSURES › CVE-2019-20085

CVE-2019-20085

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-20085 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

TVT NVMS-1000 devices suffered a directory traversal vulnerability that was actively exploited in the wild.

The NVMS-1000 software allowed attackers to access files outside the intended directory via GET /.. requests, leading to potential data exposure and system compromise. DIB organizations must ensure all deployed hardware and software are patched against known directory traversal flaws, especially those listed in CISA's KEV catalog. This failure highlights the risk of relying on unpatched or poorly maintained security controls in critical infrastructure.

Shame score — A directory traversal vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability in TVT NVMS-1000 software allows directory traversal via GET /.. requests, posing significant security risks to deployed systems.
cooey ↗ severe-fallout -0.60
Vulnerability in TVT NVMS-1000 software allows directory traversal via GET /.. requests, posing significant security risks to deployed systems.
"TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.