CVE-2019-9189
Summary
| CVE | CVE-2019-9189 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-05 18:29:00 UTC |
| Updated | 2019-07-31 16:15:00 UTC |
| Description | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Primasystems | Flexair | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prima Access Control 2.3.35 Script Upload Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Applied Risk :: Advisories | MISC | applied-risk.com | Third Party Advisory |
| Prima Systems FlexAir | CISA | MISC | www.us-cert.gov | |
| Applied Risk - Applied Risk | MISC | applied-risk.com | Third Party Advisory |
| Prima Systems FlexAir Multiple Vulnerabilities Prima Systems FlexAir Multiple Vulnerabilities - Applied Risk | MISC | applied-risk.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.