Exploits / Vulnerability Discovered : 2018-10-15 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Flir brickstream 3d+ rtsp stream disclosure is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
FLIR Systems FLIR Brickstream 3D+ Unauthenticated RTSP Stream Disclosure
Vendor: FLIR Systems, Inc.
Product web page: http://www.brickstream.com
Affected version: Firmware: 2.1.742.1842
Api: 1.0.0
Node: 0.10.33
Onvif: 0.1.1.47
Summary: The Brickstream line of sensors provides highly accurate, anonymous
information about how people move into, around, and out of physical places.
These smart devices are installed overhead inside retail stores, malls, banks,
stadiums, transportation terminals and other brick-and-mortar locations to
measure people's behaviors within the space.
Desc: The FLIR Brickstream 3D+ sensor is vulnerable to unauthenticated and
unauthorized live RTSP video stream access.
Tested on: Titan
Api/1.0.0
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience