PT-2022-25267 · Foresight · Foresight Gc3 Launch Monitor
Tom Steele
·
Published
2022-10-13
·
Updated
2022-10-14
·
CVE-2022-40187
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Foresight GC3 Launch Monitor version 1.3.15.68
Description
The issue allows for process debugging, file system modification, and terminal access as the root user through a Target Communication Framework (TCF) service. This service listens on a TCP port on all interfaces. An attacker could exploit this, potentially in conjunction with a hosted wireless access point and the known passphrase of FSSPORTS, to modify a device and steal intellectual property.
Recommendations
For Foresight GC3 Launch Monitor version 1.3.15.68, consider disabling the TCF service to prevent unauthorized access until a patch is available. Restrict access to the device and its network to minimize the risk of exploitation. Avoid using the known passphrase of FSSPORTS for wireless access points connected to these devices.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foresight Gc3 Launch Monitor