CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
97.5%
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server’s restricted path.
Vendor | Product | Version | CPE |
---|---|---|---|
flir | flir_ax8_firmware | * | cpe:2.3:o:flir:flir_ax8_firmware:*:*:*:*:*:*:*:* |
flir | flir_ax8 | - | cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:* |