CVE-2018-25137

7.5

FLIR · Brickstream 3D+

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files.

Executive summary

The FLIR Brickstream 3D+ sensor is susceptible to an unauthenticated configuration file disclosure vulnerability that allows attackers to extract sensitive system information and potentially gain unauthorized access.

Vulnerability

This vulnerability involves the lack of proper authentication checks on the getConfigExportFile.cgi endpoint and the ExportConfig REST API. An unauthenticated remote attacker can invoke these interfaces to download system configuration files, which often contain credentials or internal network details.

Business impact

Successful exploitation allows an attacker to retrieve sensitive system configuration data without any authentication. This exposure can lead to full system compromise, as the extracted information may facilitate further attacks such as authentication bypass or privilege escalation. With a CVSS score of 7.5, this high severity flaw poses a significant risk to the confidentiality and integrity of the affected devices and the networks they inhabit.

Remediation

Immediate Action: Upgrade the device firmware to the latest available version provided by FLIR to patch the vulnerable REST API endpoints.

Proactive Monitoring: Review device access logs for unauthorized requests directed at the getConfigExportFile.cgi or /restapi/system/ExportConfig endpoints.

Compensating Controls: Restrict access to the device management interface by placing it behind a firewall or on a segmented network, ensuring only trusted management IPs can reach the affected endpoints.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exploit exists via ExploitDB entry 45599.

Analyst recommendation

Given the availability of a public proof-of-concept and the ease of exploitation, this vulnerability presents a clear risk to operational security. Organizations utilizing FLIR Brickstream 3D+ sensors should verify their current firmware version and apply the vendor-supplied security update immediately. If patching is not immediately feasible, network-level access controls must be implemented to isolate the device from untrusted network segments.

More FLIR CVEs

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.