All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-08-18T17:05:48
Updated: 2024-08-03T10:21:32.676Z
Reserved: 2022-08-01T00:00:00
Link: CVE-2022-37062
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-18T18:15:08.360
Modified: 2024-11-21T07:14:22.800
Link: CVE-2022-37062
Redhat
No data.