Critical severity9.8NVD Advisory· Published Jan 1, 2018· Updated Jun 17, 2026
CVE-2018-3813
CVE-2018-3813
Description
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a direct request.
Affected products
4- cpe:2.3:o:flir:brickstream_2300_2d_firmware:2.0_4.1.53.166:*:*:*:*:*:*:*
cpe:2.3:o:flir:brickstream_2300_3d\+_firmware:2.0_4.1.53.166:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:flir:brickstream_2300_3d\+_firmware:2.0_4.1.53.166:*:*:*:*:*:*:*
- cpe:2.3:o:flir:brickstream_2300_3d_firmware:2.0_4.1.53.166:*:*:*:*:*:*:*
- Range: 4.1.53.166
Patches
Vulnerability mechanics
References
1- misteralfa-hack.blogspot.cl/2018/01/brickstream-recuento-y-seguimiento-de.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.