PT-2022-26985 · Teledyne Flir · Teledyne Flir Ax8
Ireading
·
Published
2022-12-08
·
Updated
2025-10-15
·
CVE-2022-4364
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Teledyne FLIR AX8 versions up to 1.46.16
Description
A critical vulnerability has been found in the Web Service Handler component of the affected software. The issue is related to an unknown function of the file palette.php, where the manipulation of the
palette argument leads to command injection. This allows for remote attacks.Recommendations
For versions up to 1.46.16, consider disabling the Web Service Handler component or restricting access to the palette.php file until a patch is available. As a temporary workaround, avoid using the
palette argument in the affected Web Service Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Neutralization
Special Elements Injection
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teledyne Flir Ax8