← Voltar para CVEs
CVE-2017-20212
MEDIUM6.2
Descricao
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.
Detalhes CVE
Pontuacao CVSS v3.16.2
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/8/2026
Ultima modificacao1/8/2026
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-22
Referencias
https://cxsecurity.com/issue/WLB-2017090202(disclosure@vulncheck.com)
https://packetstormsecurity.com/files/144322(disclosure@vulncheck.com)
https://web.archive.org/web/20171011125811/https://www.flir.com/security/blog/details/?ID=87043(disclosure@vulncheck.com)
https://www.exploit-db.com/exploits/42786/(disclosure@vulncheck.com)
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5434.php(disclosure@vulncheck.com)
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5434.php(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.