vendor:
FlexAir Access Control
by:
LiquidWorm
7.2
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: FlexAir Access Control
Affected Version From: 2.3.38
Affected Version To: 2.3.38
Patch Exists: YES
Related CWE: CVE-2019-7670
CPE: 2.3.38
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2018
Prima FlexAir Access Control 2.3.38 – Remote Code Execution
Authenticated Remote Root Exploit for Prima FlexAir Access Control 2.3.38 via Command Injection in SetNTPServer request, Server parameter.
Mitigation:
Update to the latest version of Prima FlexAir Access Control