Описание
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
- ExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.38 (включая)
cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.20132
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Prima Systems FlexAir devices allow authentication with MD5 hashes directly.
EPSS
Процентиль: 95%
0.20132
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287