CVE-2018-25137: FLIR Brickstream 3D+ 2.1.742.1842 Unauthenticated Config File Disclosure
FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25137?
CVE-2018-25137 is considered a medium severity vulnerability due to its potential to expose sensitive configuration files.
How do I fix CVE-2018-25137?
To fix CVE-2018-25137, it is recommended to secure the ExportConfig REST API and apply any security patches provided by FLIR.
What systems are affected by CVE-2018-25137?
CVE-2018-25137 affects FLIR Brickstream 3D+ version 2.1.742.1842.
What type of vulnerability is CVE-2018-25137?
CVE-2018-25137 is an unauthenticated vulnerability that allows unauthorized access to configuration files through the API.
What could attackers gain from exploiting CVE-2018-25137?
By exploiting CVE-2018-25137, attackers could gain access to sensitive system configuration files, potentially leading to further exploitation.