VulnerabilityAnalyzed
CVE-2018-25139
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials.
HIGH 8.7EPSS 0.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- flir/flir ax8 firmware
- Source
- disclosure@vulncheck.com
References
- https://www.exploit-db.com/exploits/45606Exploit, Third Party Advisory, VDB Entry
- https://www.flir.comProduct
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.phpExploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45606Exploit, Third Party Advisory, VDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5492.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.