vendor:
Brickstream 3D+
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Unauthenticated RTSP Stream Disclosure
287
CWE
Product Name: Brickstream 3D+
Affected Version From: Firmware: 2.1.742.1842, Api: 1.0.0, Node: 0.10.33, Onvif: 0.1.1.47
Affected Version To: Firmware: 2.1.742.1842, Api: 1.0.0, Node: 0.10.33, Onvif: 0.1.1.47
Patch Exists: YES
Related CWE: N/A
CPE: h:flir_systems:brickstream_3d+
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Titan
2018
FLIR Systems FLIR Brickstream 3D+ Unauthenticated RTSP Stream Disclosure
The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated and unauthorized live RTSP video stream access.
Mitigation:
The vendor has released a firmware update to address this vulnerability.