Cognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical Resource
Published Sep 18, 2025
7.2
HIGHCVSS 4.0
EPSS 0.31%
Description
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, which require authentication. A user with protected privileges can successfully invoke the SetSystemConfig functionality to modify relevant device properties (such as network settings), contradicting the security model proposed in the user manual.
Affected products
-
- Version 5.xStatusaffectedConstraints<=6.5.1
- Version
-
- Version 5.xStatusaffectedConstraints<=6.5.1
- Version
-
- Version 5.xStatusaffectedConstraints<=6.5.1
- Version
-
- Version 5.xStatusaffectedConstraints<=6.5.1
- Version
-
- Version 5.xStatusaffectedConstraints<=6.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cognex | In-Sight 2000 series | unaffected |
| ||||||
| Cognex | In-Sight 7000 series | unaffected |
| ||||||
| Cognex | In-Sight 8000 series | unaffected |
| ||||||
| Cognex | In-Sight 9000 series | unaffected |
| ||||||
| Cognex | In-Sight Explorer | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Cognex reports that In-Sight Explorer based vision systems are legacy products not intended for new applications. To reduce risk, asset owners are advised to switch to next generation In-Sight Vision Suite based vision systems, such as the In-Sight 2800, In-Sight 3800, In-Sight 8900 series embedded cameras.
References (2)
Change history (0)
No recorded changes yet.