CRITICAL

CVE-2022-4364

CVSS v3

9.8

CRITICAL

EPSS Score

13.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.49.16 can resolve this issue. Upgrading the affected component is advised. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."

Technical details

Published
12/8/2022

Frequently asked questions

What is CVE-2022-4364?

A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.49.16 can resolve this issue. Upgrading the affected component is advised. The vendor points out: "FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities."

Is CVE-2022-4364 actively exploited?

Active exploitation of CVE-2022-4364 has not been confirmed. The EPSS score is 13.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-4364?

CVE-2022-4364 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-4364 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.