CVE-2019-7667 describes a critical vulnerability in Prima Systems FlexAir versions 2.3.38 and prior, where the application generates database backup files with predictable names. An unauthenticated attacker can exploit this weakness by brute-forcing backup file names to download the database, revealing login credentials. This allows for full system access, bypassing authentication, and carries a CVSS score of 9.8 (Critical). While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.38CPE matchmatch criteria | cpe:2.3:a:primasystems:flexair:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.