Vulnerability Details CVE-2019-7670
Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.331
EPSS Ranking 96.7%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Products affected by CVE-2019-7670
-
cpe:2.3:a:primasystems:flexair:2.3.38