Junglewise Threat Intelligence

CVE-2024-8957: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

CVE-2024-8957 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-11-04

Executive brief

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability in the ntp_addr parameter of the /cgi-bin/param.cgi script. An authenticated attacker can execute arbitrary commands with root privileges; however, when chained with CVE-2024-8956, the vulnerability can be exploited by an unauthenticated remote attacker.

Affected products

  • PTZOptics PT30X-SDI Firmware before 6.3.40
  • PTZOptics PT30X-NDI-XX-G2 Firmware before 6.3.40

Timeline

  • 2024-09-17: disclosed: NVD Published Date
  • 2024-11-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-04: exploited: Reported as exploited in the wild by CISA and GreyNoise

Related threats