peter bassill · operator
$ cve CVE-2019-9189 JSON

CVE-2019-9189 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 11.4% (pctl 96)

Patch early

A public exploit exists.

Description

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS11.42% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2019-06-05
Last modified2026-06-17

Affected (1)

VendorProduct
primasystemsflexair

Public exploits

SourceTitleDate
exploit-dbPrima Access Control 2.3.35 - Arbitrary File Upload2019-11-12

References

→ the Explorer  ·  watch your stack  ·  NVD