Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://applied-risk.com/labs/advisories | third party advisory |
https://applied-risk.com/index.php/download_file/view/199/165 | broken link |
https://applied-risk.com/resources/ar-2019-007 | third party advisory exploit |
https://www.us-cert.gov/ics/advisories/icsa-19-211-02 | third party advisory us government resource |