CVE-2019-7280
01.07.2019, 19:15
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.Enginsight
Vendor | Product | Version |
---|---|---|
primasystems | flexair | 𝑥 ≤ 2.3.38 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration