Логотип exploitDog
bind:CVE-2019-9189
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-9189

Количество 2

Количество 2

nvd логотип

CVE-2019-9189

больше 6 лет назад

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-36c5-5h9q-3jvp

больше 3 лет назад

On Prima Systems FlexAir devices through 2.4.9api3, an authenticated user can upload Python (.py) scripts and execute arbitrary code with root privileges.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-9189

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

CVSS3: 8.8
22%
Средний
больше 6 лет назад
github логотип
GHSA-36c5-5h9q-3jvp

On Prima Systems FlexAir devices through 2.4.9api3, an authenticated user can upload Python (.py) scripts and execute arbitrary code with root privileges.

22%
Средний
больше 3 лет назад

Уязвимостей на страницу