CVE-2017-20214

7.5

FLIR Systems · Thermal Camera F/FC/PT/D

FLIR Thermal Camera firmware contains hard-coded SSH credentials that cannot be changed, allowing unauthorized remote access to the affected systems.

Executive summary

Hard-coded credentials in FLIR Thermal Camera firmware enable unauthenticated remote access, posing a severe risk of total system compromise.

Vulnerability

The device firmware incorporates hard-coded SSH credentials that are persistent and immutable by the end user. This vulnerability allows an unauthenticated attacker to establish an SSH session and gain full administrative control over the camera system.

Business impact

The presence of hard-coded credentials constitutes a critical security failure, as it provides a direct pathway for unauthorized actors to gain persistent access to the internal network or physical surveillance feeds. Given the CVSS score of 7.5, this vulnerability represents a high risk of data exfiltration, unauthorized surveillance, and the potential for the device to be used as a pivot point for further lateral movement within the network.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest firmware update that removes these hard-coded credentials, as they cannot be mitigated through configuration changes alone.

Proactive Monitoring: Implement network segmentation to isolate these camera systems from critical business infrastructure and monitor SSH traffic originating from or directed toward these devices for anomalous activity.

Compensating Controls: If a patch is unavailable, place the cameras behind a robust firewall or VPN and disable SSH access entirely if it is not required for daily operations.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented by the researcher LiquidWorm in the Exploit Database (EDB-ID 42787) and Packet Storm Security.

Analyst recommendation

The reliance on hard-coded credentials in security-sensitive hardware creates an unacceptable risk to organizational integrity. IT administrators must prioritize the identification of all affected FLIR devices and ensure they are either patched or removed from network segments that allow external or untrusted access. Immediate isolation is required until a secure firmware version is verified and applied.

More FLIR Systems CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.