CVE-2017-20213

7.5

FLIR Systems · Thermal Camera F/FC/PT/D Series

FLIR Thermal Camera F/FC/PT/D series firmware version 8.0.0.64 allows unauthenticated remote attackers to access live camera streams without credentials.

Executive summary

A critical authentication bypass vulnerability in FLIR thermal cameras allows unauthorized parties to view live video feeds remotely without valid credentials.

Vulnerability

The device suffers from a missing authentication for critical function (CWE-306), which allows an unauthenticated attacker to access the live video stream by requesting specific endpoints on the device web server.

Business impact

The ability for unauthorized parties to view live thermal video feeds poses a significant risk to physical security, privacy, and operational integrity. Given the 7.5 CVSS score, this vulnerability represents a high risk to organizations that rely on these cameras for surveillance, as it effectively renders existing access control mechanisms useless for the video stream.

Remediation

Immediate Action: Update the affected FLIR camera firmware to the latest version provided by the vendor to resolve the authentication bypass.

Proactive Monitoring: Review web server and network access logs for suspicious requests targeting the /graphics/livevideo/stream/ path, which is known to be the vulnerable endpoint.

Compensating Controls: If an immediate update is not feasible, isolate the affected camera management interfaces from public networks using a firewall or VPN to restrict access to authorized personnel only.

Exploitation status

Public Exploit Available: Yes, a published proof of concept exists via ExploitDB (EDB-ID: 42789) and Packet Storm Security.

Analyst recommendation

This vulnerability presents a clear risk to physical security deployments. It is imperative that administrators identify all vulnerable FLIR camera units within their environment and apply the necessary firmware updates immediately. If patching cannot be performed, network-level segmentation is required to prevent unauthorized access to these video streams.

More FLIR Systems CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.