VulnerabilityModified
CVE-2019-9189
The application allows the upload of arbitrary Python scripts when configuring the main central controller.
HIGH 8.8EPSS 11.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.63% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- primasystems/flexair
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/155273/Prima-Access-Control-2.3.35-Script-Upload-Remote-Code-Execution.html
- https://applied-risk.com/index.php/download_file/view/199/165Third Party Advisory
- https://applied-risk.com/labs/advisoriesThird Party Advisory
- https://applied-risk.com/resources/ar-2019-007Third Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
- http://packetstormsecurity.com/files/155273/Prima-Access-Control-2.3.35-Script-Upload-Remote-Code-Execution.html
- https://applied-risk.com/index.php/download_file/view/199/165Third Party Advisory
- https://applied-risk.com/labs/advisoriesThird Party Advisory
- https://applied-risk.com/resources/ar-2019-007Third Party Advisory
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.