vendor:
FLIR Thermal Camera FC-S/PT
by:
Gjoko 'LiquidWorm' Krstic
N/A
CVSS
HIGH
Authenticated OS Command Injection
78
CWE
Product Name: FLIR Thermal Camera FC-S/PT
Affected Version From: Firmware version: 8.0.0.64, Software version: 10.0.2.43, Release: 1.4.1, 1.4, 1.3.4 GA, 1.3.3 GA and 1.3.2
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:flir_systems:flir_thermal_camera_fc-s/pt
Platforms Tested: Linux, Nexus Server, lighttpd, PHP
2017
FLIR Systems FLIR Thermal Camera FC-S/PT Authenticated OS Command Injection
FLIR FC-S/PT series suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user.
Mitigation:
Apply the latest firmware or software update provided by FLIR Systems, Inc.