CVE-2018-3813: Infoleak
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVIUSERID and AVIUSERPASSWORD fields via a direct request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3813?
CVE-2018-3813 has a medium severity rating due to its potential for unauthorized access to sensitive configuration data.
How do I fix CVE-2018-3813?
To fix CVE-2018-3813, ensure proper access control measures are implemented to restrict access to getConfigExportFile.cgi.
What devices are affected by CVE-2018-3813?
CVE-2018-3813 affects FLIR Brickstream 2300 devices running firmware version 2.0 4.1.53.166.
What kind of data can be accessed due to CVE-2018-3813?
CVE-2018-3813 allows unauthorized access to sensitive fields like AVI_USER_ID and AVI_USER_PASSWORD.
Is there a workaround for CVE-2018-3813?
Currently, there isn't a widely recognized workaround; the best mitigation is to update the firmware or secure access to the affected CGI file.