CVE-2022-37060 Information
Aug 19, 2022
cve
Description
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server’s restricted path.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://gist.github.com/Nwqda/9e16852ab7827dc62b8e44d6180a6899 https://www.flir.com/products/ax8-automation/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: