CVE-2017-20214: FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 Hard-Coded SSH Credentials Vulnerability
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed through normal camera operations. Attackers can leverage these persistent, unmodifiable credentials to gain unauthorized remote access to the thermal camera system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20214?
CVE-2017-20214 has a high severity rating due to the potential for unauthorized remote access.
How do I fix CVE-2017-20214?
CVE-2017-20214 cannot be fixed by changing the hard-coded SSH credentials; an upgrade to a newer firmware version is recommended.
What devices are affected by CVE-2017-20214?
CVE-2017-20214 affects FLIR Thermal Camera models F/FC/PT/D running firmware version 8.0.0.64.
What are the risks associated with CVE-2017-20214?
The risks include potential unauthorized access and control over thermal camera systems, leading to data breaches.
Is there a workaround for CVE-2017-20214?
There is no viable workaround for CVE-2017-20214 as the hard-coded credentials cannot be changed.