vendor:
FlexAir Access Control
by:
LiquidWorm
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: FlexAir Access Control
Affected Version From: 2.3.35
Affected Version To: 2.3.35
Patch Exists: YES
Related CWE: CVE-2019-7666, CVE-2019-7667
CPE: a:computrols:flexair_access_control:2.3.35
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: NA
2019
FlexAir Access Control 2.3.35 – Authentication Bypass
Prima FlexAir Access Control 2.3.35 Database Backup Predictable Name Exploit allows an attacker to bypass authentication by downloading the backup config file and extracting the MD5 hashes of the usernames and passwords from the database.
Mitigation:
Upgrade to version 2.4 or later.