{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-27T01:48:29.580","vulnerabilities":[{"cve":{"id":"CVE-2024-3013","sourceIdentifier":"cna@vuldb.com","published":"2024-03-28T01:15:47.997","lastModified":"2026-06-17T07:43:07.750","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Registration. Executing manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 1.49.16 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor points out: \"FLIR AX8 internal web site has been refactored to be able to handle the reported vulnerabilities.\""},{"lang":"es","value":"Se encontró una vulnerabilidad en FLIR AX8 hasta 1.46.16. Ha sido calificada como crítica. Este problema afecta un procesamiento desconocido del archivo /tools/test_login.php?action=register del componente Registro de usuario. La manipulación conduce a una autorización inadecuada. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-258299. NOTA: Se contactó primeramente con el proveedor sobre esta divulgación, pero no respondió de ninguna manera."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"Teledyne FLIR","product":"AX8","modules":["User Registration"],"versions":[{"version":"1.46.0","status":"affected"},{"version":"1.46.1","status":"affected"},{"version":"1.46.2","status":"affected"},{"version":"1.46.3","status":"affected"},{"version":"1.46.4","status":"affected"},{"version":"1.46.5","status":"affected"},{"version":"1.46.6","status":"affected"},{"version":"1.46.7","status":"affected"},{"version":"1.46.8","status":"affected"},{"version":"1.46.9","status":"affected"},{"version":"1.46.10","status":"affected"},{"version":"1.46.11","status":"affected"},{"version":"1.46.12","status":"affected"},{"version":"1.46.13","status":"affected"},{"version":"1.46.14","status":"affected"},{"version":"1.46.15","status":"affected"},{"version":"1.46.16","status":"affected"},{"version":"1.49.16","status":"unaffected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"flir","product":"flir_ax8_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:flir:flir_ax8_firmware:1.46.0:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.1:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.10:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.11:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.12:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.13:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.14:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.15:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.16:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.2:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.3:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.4:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.5:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.6:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.7:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.8:*:*:*:*:*:*:*","cpe:2.3:o:flir:flir_ax8_firmware:1.46.9:*:*:*:*:*:*:*"],"versions":[{"version":"1.46.0","status":"affected"},{"version":"1.46.1","status":"affected"},{"version":"1.46.10","status":"affected"},{"version":"1.46.11","status":"affected"},{"version":"1.46.12","status":"affected"},{"version":"1.46.13","status":"affected"},{"version":"1.46.14","status":"affected"},{"version":"1.46.15","status":"affected"},{"version":"1.46.16","status":"affected"},{"version":"1.46.2","status":"affected"},{"version":"1.46.3","status":"affected"},{"version":"1.46.4","status":"affected"},{"version":"1.46.5","status":"affected"},{"version":"1.46.6","status":"affected"},{"version":"1.46.7","status":"affected"},{"version":"1.46.8","status":"affected"},{"version":"1.46.9","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-28T18:31:24.496579Z","id":"CVE-2024-3013","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"},{"lang":"en","value":"CWE-285"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:flir:flir_ax8_firmware:*:*:*:*:*:*:*:*","versionStartIncluding":"1.46.0","versionEndIncluding":"1.46.16","matchCriteriaId":"38C9FAE6-3C28-4C1F-AD3D-07F554ADEA95"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:flir:flir_ax8:-:*:*:*:*:*:*:*","matchCriteriaId":"2A4DACB7-0558-4C74-8EDB-39591236ADEE"}]}]}],"references":[{"url":"https://h0e4a0r1t.github.io/2024/vulns/FLIR-AX8%20Fixed%20Thermal%20Cameras%20Register%20any%20user%20in%20the%20background--test_login.php.pdf","source":"cna@vuldb.com","tags":["Broken Link"]},{"url":"https://vuldb.com/?ctiid.258299","source":"cna@vuldb.com","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.258299","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.301588","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://h0e4a0r1t.github.io/2024/vulns/FLIR-AX8%20Fixed%20Thermal%20Cameras%20Register%20any%20user%20in%20the%20background--test_login.php.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://vuldb.com/?ctiid.258299","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.258299","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.301588","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]}]}}]}