CVE-2019-7670 is a critical OS command injection vulnerability affecting Prima Systems FlexAir versions 2.3.38 and earlier. This flaw allows authenticated attackers to execute arbitrary commands on the underlying operating system by manipulating special characters in application inputs. With a CVSS score of 7.2 (HIGH), this vulnerability presents a significant risk, enabling complete compromise of confidentiality, integrity, and availability. While not actively exploited in the wild, public exploit code is available, and it has garnered notable community and media attention, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.38CPE matchmatch criteria | cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.