CVE-2017-20212: FLIR Thermal Camera F/FC/PT/D 8.0.0.64 Information Disclosure via File Reading
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20212?
CVE-2017-20212 has a severity rating of medium due to its potential for information disclosure by unauthenticated attackers.
How do I fix CVE-2017-20212?
To fix CVE-2017-20212, upgrade the firmware of the FLIR Thermal Camera F/FC/PT/D to the latest version provided by the vendor.
What type of vulnerability is CVE-2017-20212?
CVE-2017-20212 is an information disclosure vulnerability that allows unauthorized access to files on the device.
Who is affected by CVE-2017-20212?
Users of the FLIR Thermal Camera F/FC/PT/D using firmware version 8.0.0.64 are affected by CVE-2017-20212.
Can CVE-2017-20212 be exploited remotely?
Yes, CVE-2017-20212 can be exploited remotely by unauthenticated attackers through specific input parameters.