PT-2024-13348 · Teledyne Flir · Teledyne Flir M300

Published

2024-05-01

·

Updated

2024-11-04

·

CVE-2023-46294

CVSS v3.1

3.4

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Teledyne FLIR M300 versions 2.00 through 2.00-19
Description An issue was discovered where user account passwords are encrypted locally and can be decrypted to cleartext passwords using the umSetup utility, which requires root permissions to execute.
Recommendations For Teledyne FLIR M300 versions 2.00 through 2.00-19, consider restricting access to the umSetup utility to prevent unauthorized decryption of user account passwords. As a temporary workaround, limit the use of root permissions to execute the umSetup utility until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-46294

Affected Products

Teledyne Flir M300