An issue was discovered in Teledyne FLIR M300 2.00-19. User account passwords are encrypted locally, and can be decrypted to cleartext passwords using the utility umSetup. This utility requires root permissions to execute.
https://gitlab.com/loudmouth-security/vulnerability-disclosures/cve-2023-46294