9
CVSSv2

CVE-2019-9189

Published: 05/06/2019 Updated: 31/07/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated malicious user to gain full system access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

primasystems flexair

Exploits

# Exploit Title: Prima Access Control 2335 - Arbitrary File Upload # Google Dork: NA # Date: 2019-11-11 # Exploit Author: LiquidWorm # Vendor Homepage: wwwcomputrolscom/capabilities-cbas-web/ # Software Link: wwwcomputrolscom/building-automation-software/ # Version: 2335 # Tested on: NA # CVE : CVE-2019-9189 # Advisory: http ...
Prima Access Control version 2335 authenticated python script upload remote root code execution exploit ...