Описание
Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.
Ссылки
- Broken Link
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party AdvisoryUS Government Resource
- Broken Link
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.38 (включая)
cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01101
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Prima Systems FlexAir devices have Hard-coded Credentials.
EPSS
Процентиль: 78%
0.01101
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-798