VYPR

M300

by Flir

CVEs (2)

  • CVE-2023-46295CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Teledyne FLIR M300 2.00-19. Unauthenticated remote code execution can occur in the web server. An attacker can exploit this by sending a POST request to the vulnerable PHP page. An attacker can elevate to root permissions with Sudo.

  • CVE-2023-46294LowMay 1, 2024
    risk 0.22cvss 3.4epss 0.00

    An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.