Enms maintains a narrowly scoped product portfolio concentrated in a single network management system that, despite modest disclosure volume, carries elevated severity risk through its administrative and system-access responsibilities. The recurring vulnerability pattern centers on path-traversal weaknesses that enable unauthorized file access and directory manipulation, a characteristic flaw class in management and control-plane software where input validation at trust boundaries is critical. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-11664CRITICAL A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of | Nov 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-46645HIGH eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files. | Sep 20, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-46649HIGH eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder. | Sep 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-46648HIGH eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder. | Sep 20, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-46647MEDIUM eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files. | Sep 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-46646MEDIUM eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file. | Sep 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-46644MEDIUM eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file. | Sep 20, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enms.
Media articles that mention a CVE ID that affects a product developed by Enms — matched by CVE ID, not by vendor name.