CVE-2022-37062: SQL Injection
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37062?
CVE-2022-37062 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive database information.
How do I fix CVE-2022-37062?
To fix CVE-2022-37062, update the FLIR AX8 thermal sensor camera firmware to version 1.47.00 or later.
What types of attacks can exploit CVE-2022-37062?
CVE-2022-37062 can be exploited by an unauthenticated remote attacker via directory traversal to access the SQLite users database.
What devices are affected by CVE-2022-37062?
CVE-2022-37062 affects all FLIR AX8 thermal sensor cameras running firmware versions up to and including 1.46.16.
Is user authentication required to exploit CVE-2022-37062?
No, CVE-2022-37062 can be exploited without any user authentication.