SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9189

The application allows the upload of arbitrary Python scripts when configuring the main central controller.

HIGH 8.8EPSS 11.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 11.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
11.63% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
primasystems/flexair
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.