Known Vulnerabilities for products from Primasystems

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Primasystems".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2019-9189 json Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when confi... 8.8 - HIGH 2019-06-05 2019-07-31
CVE-2019-7672 json Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and p... 8.8 - HIGH 2019-06-05 2022-10-14
CVE-2019-7671 json Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned... 9 - CRITICAL 2019-06-05 2022-10-25
CVE-2019-7670 json Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify ... 7.2 - HIGH 2019-07-01 2022-10-21
CVE-2019-7669 json Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a r... 8.8 - HIGH 2019-07-01 2022-10-21
CVE-2019-7668 json Prima Systems FlexAir devices have Default Credentials. 9.8 - CRITICAL 2019-07-01 2020-08-24
CVE-2019-7667 json Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, an... 9.8 - CRITICAL 2019-07-01 2022-10-21
CVE-2019-7666 json Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of ... 8.8 - HIGH 2019-07-01 2022-10-25
CVE-2019-7281 json Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow ... 8.8 - HIGH 2019-07-01 2022-10-25
CVE-2019-7280 json Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute f... 8.8 - HIGH 2019-07-01 2022-10-25

Known software with vulnerabilities from Primasystems

Type Vendor Product Version
ApplicationPrimasystemsFlexair2.3.38

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report