CVE-2024-8956

Confirmed PUBLISHED

PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication

PTZOptics · PT30X-SDI, PT30X-NDI
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.1 Critical

At a Glance

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

cisa nessus_scanner
CVE Published
Sep 17, 2024
Exploitation Reported
Nov 04, 2024
CVSS
9.1 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
ptzoptics
pt30x-sdi_firmware

0 to < 6.3.40

Affected
ptzoptics
pt30x-ndi-xx-g2_firmware

0 to < 6.3.40

Affected
PTZOptics
PT30X-SDI

0 to < 6.3.40

Affected
PTZOptics
PT30X-NDI

0 to < 6.3.40

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.