#VU20480 Improper Authentication in FlexAir - CVE-2019-7666
Published: August 30, 2019 / Updated: June 17, 2021
FlexAir
Prima Systems
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the application allows improper authentication with the MD5 hash value of the password. A remote authenticated attacker can authenticate to the application without knowing the password of a specific username if previously obtained the database with all the MD5 hash passwords.