CVE-2024-3013
Executing manipulation can lead to improper authorization.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Registration. Executing manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 1.49.16 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 22.99% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-285
- Affected
- flir/flir ax8 firmware
- Source
- cna@vuldb.com
References
- https://h0e4a0r1t.github.io/2024/vulns/FLIR-AX8%20Fixed%20Thermal%20Cameras%20Register%20any%20user%20in%20the%20background--test_login.php.pdfBroken Link
- https://vuldb.com/?ctiid.258299Permissions Required, VDB Entry
- https://vuldb.com/?id.258299Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.301588Third Party Advisory, VDB Entry
- https://h0e4a0r1t.github.io/2024/vulns/FLIR-AX8%20Fixed%20Thermal%20Cameras%20Register%20any%20user%20in%20the%20background--test_login.php.pdfBroken Link
- https://vuldb.com/?ctiid.258299Permissions Required, VDB Entry
- https://vuldb.com/?id.258299Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.301588Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.