Описание
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
Ссылки
- Not ApplicableThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- Not ApplicableThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.38 (включая)
cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.0028
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Prima Systems FlexAir devices allow Cross-Site Request Forgery (CSRF).
EPSS
Процентиль: 51%
0.0028
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352