PT-2022-25267 · Foresight · Foresight Gc3 Launch Monitor

Tom Steele

·

Published

2022-10-13

·

Updated

2022-10-14

·

CVE-2022-40187

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foresight GC3 Launch Monitor version 1.3.15.68
Description The issue allows for process debugging, file system modification, and terminal access as the root user through a Target Communication Framework (TCF) service. This service listens on a TCP port on all interfaces. An attacker could exploit this, potentially in conjunction with a hosted wireless access point and the known passphrase of FSSPORTS, to modify a device and steal intellectual property.
Recommendations For Foresight GC3 Launch Monitor version 1.3.15.68, consider disabling the TCF service to prevent unauthorized access until a patch is available. Restrict access to the device and its network to minimize the risk of exploitation. Avoid using the known passphrase of FSSPORTS for wireless access points connected to these devices.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-40187

Affected Products

Foresight Gc3 Launch Monitor