CRITICAL

CVE-2024-8956

Ptzoptics Pt30x Sdi Firmware 2024-09-17 CVSS v3.1
CVSS
9.1
KEV

Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

Summary dbcve.org

PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 have an authentication bypass vulnerability in /cgi-bin/param.cgi. When HTTP requests are sent without an Authorization header, the endpoint does not enforce authentication, allowing unauthenticated remote attackers to read sensitive data including usernames, password hashes, and configuration details, and to modify or overwrite configuration files entirely.

Mitigation

Upgrade camera firmware to version 6.3.40 or later. If immediate patching is not feasible, implement network segmentation or firewall rules to restrict unauthorized access to the camera's web interface.

Proof of Concept

Weakness (CWE)

CWE-306 Missing Authentication
CWE-287 Improper Authentication

EPSS Score

61.28%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE