peter bassill · operator
$ cve CVE-2019-7667 JSON

CVE-2019-7667

9.8
CRITICAL · CVSS 3.1 · EPSS 4.5% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and disclose login information, which can allow the attacker to bypass authentication and have full access to the system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.5% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-330
On CISA KEVno
Public exploitnone known
Published2019-07-01
Last modified2026-06-17

Affected (1)

VendorProduct
primasystemsflexair

References

→ the Explorer  ·  watch your stack  ·  NVD