CVE-2023-46294: Low severity Teledyne FLIR M300 vulnerability
Published May 1, 2024
·Updated
An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.
Affected Software
1 affected component
Teledyne FLIR M300
Event History
May 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46294?
CVE-2023-46294 has a critical severity level due to the potential for unauthorized decryption of user account passwords.
2
How do I fix CVE-2023-46294?
To fix CVE-2023-46294, update the Teledyne FLIR M300 to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2023-46294?
Users of Teledyne FLIR M300 version 2.00-19 are affected by CVE-2023-46294.
4
What are the implications of CVE-2023-46294?
CVE-2023-46294 can lead to the exposure of sensitive user credentials if an attacker gains root access.
5
What can be done to mitigate CVE-2023-46294?
To mitigate CVE-2023-46294, limit root access and monitor for any unauthorized attempts to execute the umSetup utility.