← back
CVE-2017-20215highCWE-78

FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 Authenticated OS Command Injection

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.7epss 14%
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute shell commands with root privileges. Authenticated attackers can inject arbitrary shell commands through unvalidated input parameters to gain complete control of the thermal camera system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N