Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqmc-5wjw-632r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Prima Systems FlexAir devices allow Authenticated Command Injection resulting in Root Remote Code Execution.

Prima Systems FlexAir devices allow Authenticated Command Injection resulting in Root Remote Code Execution.

EPSS

Процентиль: 96%
0.27173
Средний

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
больше 6 лет назад

Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.

EPSS

Процентиль: 96%
0.27173
Средний

7.2 High

CVSS3

Дефекты

CWE-78