FLIR Systems AX8 Cameras Path Traversal (CVE-2023-51127)

high Tenable OT Security Plugin ID 505189

Synopsis

The remote OT asset is affected by a vulnerability.

Description

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction.
This vulnerability allows an unauthenticated, remote attacker to obtain arbitrary sensitive file contents by uploading a specially crafted symbolic link file. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://github.com/risuxx/CVE-2023-51127

Plugin Details

Severity: High

ID: 505189

File Name: tenable_ot_flirsystems_CVE-2023-51127.nasl

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 2/19/2026

Updated: 2/19/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/o:flir:flir_ax8_firmware:1.46.16

Required KB Items: Tenable.ot/FLIRSystems

Exploit Ease: No known exploits are available

Patch Publication Date: 1/10/2024

Vulnerability Publication Date: 1/10/2024

Reference Information

CVE: CVE-2023-51127

CWE: 22