PT-2022-26985 · Teledyne Flir · Teledyne Flir Ax8

Ireading

·

Published

2022-12-08

·

Updated

2025-10-15

·

CVE-2022-4364

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Teledyne FLIR AX8 versions up to 1.46.16
Description A critical vulnerability has been found in the Web Service Handler component of the affected software. The issue is related to an unknown function of the file palette.php, where the manipulation of the palette argument leads to command injection. This allows for remote attacks.
Recommendations For versions up to 1.46.16, consider disabling the Web Service Handler component or restricting access to the palette.php file until a patch is available. As a temporary workaround, avoid using the palette argument in the affected Web Service Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Neutralization

Special Elements Injection

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-4364

Affected Products

Teledyne Flir Ax8