PoC Index

CVE-2019-7666

HIGH 8.8EPSS 14.8%

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
14.82% chance of exploitation in the next 30 days, 96th percentile
Published
2019-07-01
Updated
2024-08-04

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related