vendor:
Thermal Traffic Cameras
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Unauthenticated Device Manipulation
284
CWE
Product Name: Thermal Traffic Cameras
Affected Version From: V1.01-0bb5b27
Affected Version To: V1.06
Patch Exists: YES
Related CWE: N/A
CPE: h:flir:thermal_traffic_cameras
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: nginx/1.12.1, nginx/1.10.2, nginx/1.8.0, Websocket/13 (RFC 6455)
2018
FLIR Thermal Traffic Cameras 1.01-0bb5b27 – Information Disclosure
FLIR thermal traffic cameras suffer from an unauthenticated device manipulation vulnerability utilizing the websocket protocol. The affected FLIR Intelligent Transportation Systems - ITS models use an in-house developed websocket protocol implementation, which is vulnerable to manipulation.
Mitigation:
The vendor has released firmware updates for the affected models. Additionally, users should follow the vendor's cyber hardening guide to ensure the security of their devices.