CVE-2017-20212
MEDIUMFLIR Thermal Camera F/FC/PT/D <8.0.0.64 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20212. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file read vulnerability in FLIR Systems' thermal cameras due to improper input validation in the `readFile` function. Attackers can read sensitive files like `/etc/passwd` or configuration files without authentication.
Description
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.
Exploits (1)
This exploit demonstrates an arbitrary file read vulnerability in FLIR Systems' thermal cameras due to improper input validation in the `readFile` function. Attackers can read sensitive files like `/etc/passwd` or configuration files without authentication.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N