CVE-2019-6716 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in Wicket Core affecting LogonBox Nervepoint Access Manager versions 2013 through 2017. This flaw allows remote attackers to enumerate Active Directory usernames and group names, and modify back-end server jobs, potentially leading to a Denial of Service. With a CVSS score of 9.4 (CRITICAL), it has a low attack complexity and requires no user interaction or privileges, enabling high impact on integrity and availability. While not listed on KEV or the Hot List, a public exploit (EDB-46254) exists, though there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:logonbox:nervepoint_access_manager:1.2:rg10:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:logonbox:nervepoint_access_manager:1.2:rg3:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:logonbox:nervepoint_access_manager:1.2:rg4:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:logonbox:nervepoint_access_manager:1.2:rg5:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:logonbox:nervepoint_access_manager:1.2:rg6:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.