vendor:
Thermal Traffic Cameras
by:
Gjoko 'LiquidWorm' Krstic
CVSS
HIGH
Unauthorized and Unauthenticated Live RTSP Video Stream Access
N/A
CWE
Product Name: Thermal Traffic Cameras
Affected Version From: V1.01-0bb5b27 (TrafiOne), E1.00.09 (TI BPL2 EDGE), V1.02.P01 (TI x-stream), V1.05.P01 (ThermiCam), V1.04.P02 (ThermiCam), V1.04 (ThermiCam), V1.01.P02 (ThermiCam), V1.05.P03 (TrafiSense), V1.06 (VIP-IP), V1.02.P02 (TrafiRadar)
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: nginx/1.12.1, nginx/1.10.2, nginx/1.8.0, Websocket/13 (RFC 6455)
2018
FLIR Thermal Traffic Cameras 1.01-0bb5b27 – RTSP Stream Disclosure
FLIR thermal traffic cameras suffer from an unauthenticated and unauthorized live RTSP video stream access.
Mitigation:
Upgrade to the latest version of the firmware released by the vendor.