CVE-2022-37063: XSS
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37063?
CVE-2022-37063 is considered to have a medium severity due to its potential for Cross Site Scripting attacks.
How do I fix CVE-2022-37063?
To fix CVE-2022-37063, upgrade the FLIR AX8 thermal sensor cameras to firmware version 1.46.17 or later.
What are the consequences of exploiting CVE-2022-37063?
Exploiting CVE-2022-37063 could allow an authenticated attacker to execute arbitrary JavaScript code in the web management interface.
Who is affected by CVE-2022-37063?
All users of the FLIR AX8 thermal sensor cameras running firmware version 1.46.16 or earlier are affected by CVE-2022-37063.
Is CVE-2022-37063 a hardware or software vulnerability?
CVE-2022-37063 is a software vulnerability affecting the firmware of FLIR AX8 cameras.