6.5
CVSSv2

CVE-2019-7666

Published: 01/07/2019 Updated: 25/10/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

primasystems flexair

Exploits

# Exploit Title: FlexAir Access Control 2335 - Authentication Bypass # Google Dork: NA # Date: 2019-11-11 # Exploit Author: LiquidWorm # Vendor Homepage: wwwcomputrolscom/capabilities-cbas-web/ # Software Link: wwwcomputrolscom/building-automation-software/ # Version: 2335 # Tested on: NA # CVE : CVE-2019-7666, CVE-2019-7667 ...
Prima FlexAir Access Control version 2335 database backup predictable name exploit ...