CVE-2019-7666
Summary
| CVE | CVE-2019-7666 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-01 19:15:00 UTC |
| Updated | 2022-10-25 15:29:00 UTC |
| Description | Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Primasystems | Flexair | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prima Systems FlexAir Multiple Vulnerabilities Prima Systems FlexAir Multiple Vulnerabilities - Applied Risk | MISC | www.applied-risk.com | Third Party Advisory |
| Applied Risk :: Advisories | MISC | applied-risk.com | Third Party Advisory |
| Prima Systems FlexAir | CISA | MISC | www.us-cert.gov | |
| Prima FlexAir Access Control 2.3.35 Database Backup Predictable Name ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.