CVE-2019-7666 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 14.8% (pctl 97)
Patch early
A public exploit exists.
Description
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 14.82% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-07-01 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| primasystems | flexair |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FlexAir Access Control 2.3.35 - Authentication Bypass | 2019-11-12 |
References
- http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html
- https://applied-risk.com/labs/advisories
- https://www.applied-risk.com/resources/ar-2019-007
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
- http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html
- https://applied-risk.com/labs/advisories
- https://www.applied-risk.com/resources/ar-2019-007
- https://www.us-cert.gov/ics/advisories/icsa-19-211-02
→ the Explorer · watch your stack · NVD