ZeroHour

CVE-2019-7666

PoC
CVSS 3.1
8.8 high
EPSS
15%p96
Published
()
Modified
Description

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

Vendors
primasystems
Products
flexair
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.