HIGH

CVE-2024-8957

Ptzoptics Pt30x Sdi Firmware 2024-09-17 CVSS v3.1
CVSS
7.2
KEV

Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.

Summary dbcve.org

PTZOptics PT30X-SDI/NDI-xx cameras before firmware 6.3.40 contain an OS command injection vulnerability in the ntp_addr configuration parameter. Insufficient validation of this value allows arbitrary command execution when the ntp_client service starts. When chained with CVE-2024-8956 (authentication bypass), a remote unauthenticated attacker can achieve remote code execution.

Mitigation

Upgrade PTZOptics PT30X-SDI/NDI-xx firmware to version 6.3.40 or later to remediate this vulnerability. Until patched, restrict network exposure of the device and monitor for suspicious NTP configuration changes.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

80.96%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE