An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 04 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Teledyne
Teledyne flir M300
Weaknesses CWE-312
CPEs cpe:2.3:a:teledyne:flir_m300:*:*:*:*:*:*:*:*
Vendors & Products Teledyne
Teledyne flir M300
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-04T17:09:19.968Z

Reserved: 2023-10-21T00:00:00

Link: CVE-2023-46294

cve-icon Vulnrichment

Updated: 2024-08-02T20:45:40.659Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-01T20:15:12.267

Modified: 2024-11-21T08:28:14.570

Link: CVE-2023-46294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.