Vulnerability Description
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the known passphrase of FSSPORTS, an attacker could use this service to modify a device and steal intellectual property.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foresightsports | Gc3 Launch Monitor Firmware | < 1.5.0.2 |
| Foresightsports | Gc3 Launch Monitor | - |
| Bushnellgolf | Launch Pro Firmware | < 1.5.0.2 |
| Bushnellgolf | Launch Pro | - |
Related Weaknesses (CWE)
References
- https://github.com/atredispartners/advisories/blob/master/ATREDIS-2022-0003.mdExploitThird Party Advisory
- https://wiki.eclipse.org/TCFThird Party Advisory
- https://www.bushnellgolf.com/products/launch-monitors/launch-pro/Product
- https://www.foresightsports.com/gc3Product
- https://github.com/atredispartners/advisories/blob/master/ATREDIS-2022-0003.mdExploitThird Party Advisory
- https://wiki.eclipse.org/TCFThird Party Advisory
- https://www.bushnellgolf.com/products/launch-monitors/launch-pro/Product
- https://www.foresightsports.com/gc3Product
FAQ
What is CVE-2022-40187?
CVE-2022-40187 is a vulnerability with a CVSS score of 8.0 (HIGH). Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file sy...
How severe is CVE-2022-40187?
CVE-2022-40187 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40187?
Check the references section above for vendor advisories and patch information. Affected products include: Foresightsports Gc3 Launch Monitor Firmware, Foresightsports Gc3 Launch Monitor, Bushnellgolf Launch Pro Firmware, Bushnellgolf Launch Pro.