CVE-2019-7666: Primasystems Flexair
High severity, CVSS 8.8. EPSS: 14.8% chance of exploitation in the next 30 days.
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.
Affected products
- Primasystems Flexair: up to and including 2.3.38
Published 2019-07-01. Last modified 2026-06-17.