EXPOSURES › CVE-2019-20085
CVE-2019-20085
HIGH ⌖ ON CISA KEV · EXPLOITEDTVT NVMS-1000 devices suffered a directory traversal vulnerability that was actively exploited in the wild.
The NVMS-1000 software allowed attackers to access files outside the intended directory via GET /.. requests, leading to potential data exposure and system compromise. DIB organizations must ensure all deployed hardware and software are patched against known directory traversal flaws, especially those listed in CISA's KEV catalog. This failure highlights the risk of relying on unpatched or poorly maintained security controls in critical infrastructure.
Shame score — A directory traversal vulnerability was actively exploited in the wild and included in CISA's KEV catalog, indicating negligent patching and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
"TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests."