Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2gq-4xqf-ccqf

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5

Описание

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

EPSS

Процентиль: 30%
0.00111
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

EPSS

Процентиль: 30%
0.00111
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306