peter bassill · operator
$ cve CVE-2019-7666 JSON

CVE-2019-7666 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 14.8% (pctl 97)

Patch early

A public exploit exists.

Description

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.82% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2019-07-01
Last modified2026-06-17

Affected (1)

VendorProduct
primasystemsflexair

Public exploits

SourceTitleDate
exploit-dbFlexAir Access Control 2.3.35 - Authentication Bypass2019-11-12

References

→ the Explorer  ·  watch your stack  ·  NVD