Junglewise Threat Intelligence

CVE-2024-8956: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

CVE-2024-8956 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2024-11-04

Executive brief

PTZOptics PT30X-SDI/NDI cameras fail to enforce authentication for the /cgi-bin/param.cgi script when an HTTP Authorization header is missing. This allows a remote, unauthenticated attacker to leak sensitive data including credentials and configuration details, or modify the device configuration.

Affected products

  • PTZOptics PT30X-SDI Firmware before 6.3.40
  • PTZOptics PT30X-NDI-XX-G2 Firmware before 6.3.40

Timeline

  • 2024-09-17: disclosed: NVD Published Date
  • 2024-11-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-04: exploited: Reported as exploited in the wild in advisory summary

Related threats