{"api_version":"1","generated_at":"2026-07-23T11:14:49+00:00","cve":"CVE-2019-7666","urls":{"html":"https://cve.report/CVE-2019-7666","api":"https://cve.report/api/cve/CVE-2019-7666.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-7666","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-7666"},"summary":{"title":"CVE-2019-7666","description":"Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-01 19:15:00","updated_at":"2022-10-25 15:29:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://www.applied-risk.com/resources/ar-2019-007","name":"https://www.applied-risk.com/resources/ar-2019-007","refsource":"MISC","tags":["Third Party Advisory"],"title":"Prima Systems FlexAir Multiple Vulnerabilities Prima Systems FlexAir Multiple Vulnerabilities - Applied Risk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://applied-risk.com/labs/advisories","name":"https://applied-risk.com/labs/advisories","refsource":"MISC","tags":["Third Party Advisory"],"title":"Applied Risk :: Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-211-02","name":"https://www.us-cert.gov/ics/advisories/icsa-19-211-02","refsource":"MISC","tags":[],"title":"Prima Systems FlexAir | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html","name":"http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html","refsource":"MISC","tags":[],"title":"Prima FlexAir Access Control 2.3.35 Database Backup Predictable Name ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-7666","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-7666","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"7666","vulnerable":"1","versionEndIncluding":"2.3.38","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"primasystems","cpe5":"flexair","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-7666","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://applied-risk.com/labs/advisories","refsource":"MISC","name":"https://applied-risk.com/labs/advisories"},{"refsource":"MISC","name":"https://www.applied-risk.com/resources/ar-2019-007","url":"https://www.applied-risk.com/resources/ar-2019-007"},{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-19-211-02","url":"https://www.us-cert.gov/ics/advisories/icsa-19-211-02"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html","url":"http://packetstormsecurity.com/files/155262/Prima-FlexAir-Access-Control-2.3.35-Database-Backup-Predictable-Name.html"}]}},"nvd":{"publishedDate":"2019-07-01 19:15:00","lastModifiedDate":"2022-10-25 15:29:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:*","versionEndIncluding":"2.3.38","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"7666","Ordinal":"145481","Title":"CVE-2019-7666","CVE":"CVE-2019-7666","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"7666","Ordinal":"1","NoteData":"Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"7666","Ordinal":"2","NoteData":"2019-07-01","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"7666","Ordinal":"3","NoteData":"2019-11-12","Type":"Other","Title":"Modified"}]}}}