CVE-2019-7666
PoC —CVSS 3.1
8.8 high
EPSS
15%p96
Published
()
Modified
Description
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.
- Vendors
- primasystems
- Products
- flexair
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.