It's fine, you're not running a network-accessible part of the service on unpatched software. The only input this part of the software requires is trusted configuration data and a video feed which could hypothetically be malicious, but then the question becomes why you're running an adversarial camera on your network, and why you're allowing it to connect to the internet to fetch latest exploits and C&C instructions.
You can also transcode the video before feeding it to any outdated software and run it in a VM if you're paranoid.
You can also transcode the video before feeding it to any outdated software and run it in a VM if you're paranoid.