Known Vulnerabilities for Flexair by Primasystems
Listed below are 10 of the newest known vulnerabilities associated with "Flexair" by "Primasystems".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-9189 json | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when confi... | 8.8 - HIGH | 2019-06-05 | 2019-07-31 |
| CVE-2019-7672 json | Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and p... | 8.8 - HIGH | 2019-06-05 | 2022-10-14 |
| CVE-2019-7671 json | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned... | 9 - CRITICAL | 2019-06-05 | 2022-10-25 |
| CVE-2019-7670 json | Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify ... | 7.2 - HIGH | 2019-07-01 | 2022-10-21 |
| CVE-2019-7669 json | Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a r... | 8.8 - HIGH | 2019-07-01 | 2022-10-21 |
| CVE-2019-7668 json | Prima Systems FlexAir devices have Default Credentials. | 9.8 - CRITICAL | 2019-07-01 | 2020-08-24 |
| CVE-2019-7667 json | Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, an... | 9.8 - CRITICAL | 2019-07-01 | 2022-10-21 |
| CVE-2019-7666 json | Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of ... | 8.8 - HIGH | 2019-07-01 | 2022-10-25 |
| CVE-2019-7281 json | Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow ... | 8.8 - HIGH | 2019-07-01 | 2022-10-25 |
| CVE-2019-7280 json | Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute f... | 8.8 - HIGH | 2019-07-01 | 2022-10-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Primasystems | Flexair | 2.3.38 |