Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flexair CRITICAL 9.8
CVE-2019-7667

Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use br…

Fix: after 2.3.38
Fix from $2,300 2019-07-01
Flexair CRITICAL 9.8
CVE-2019-7668

Prima Systems FlexAir devices have Default Credentials.

Fix: after 2.3.38
Fix from $2,300 2019-07-01
Flexair HIGH 8.8
CVE-2019-7280

Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Flexair HIGH 8.8
CVE-2019-7281

Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Flexair HIGH 8.8
CVE-2019-7666EPSS 15%

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Flexair HIGH 8.8
CVE-2019-7669EPSS 31%

Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated atta…

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Flexair HIGH 7.2
CVE-2019-7670EPSS 18%

Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command …

Fix: after 2.3.38
Fix from $1,950 2019-07-01
Flexair CRITICAL 9.0
CVE-2019-7671EPSS 8%

Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may …

Fix: after 2.3.38
Fix from $2,300 2019-06-05
Flexair HIGH 8.8
CVE-2019-7672

Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow…

Fix: after 2.3.38
Fix from $1,950 2019-06-05
Flexair HIGH 8.8
CVE-2019-9189EPSS 12%

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central …

Fix: after 2.3.38
Fix from $1,950 2019-06-05