Description
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across multiple camera series without requiring any authentication.
Problem types
Missing Authentication for Critical Function
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
cxsecurity.com/issue/WLB-2017090204
www.exploit-db.com/exploits/42789/
www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5435.php
www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5435.php (Zero Science Lab Vulnerability Advisory)
www.exploit-db.com/exploits/42789/ (Exploit Database Entry 42789)
packetstormsecurity.com/files/144323 (Packet Storm Security Exploit Archive)
cxsecurity.com/issue/WLB-2017090204 (CXSecurity Vulnerability Listing)
web.archive.org/....flir.com/security/blog/details/?ID=87043 (Archived FLIR Security Advisory)