Skip to content
COOEY

EXPOSURES › CVE-2024-8956

CVE-2024-8956

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-8956 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedauth-bypasssupply-chainransomware

PTZOptics PT30X-SDI/NDI cameras allow remote authentication bypass via IDOR, enabling root RCE when combined with CVE-2024-8957.

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that bypasses authentication for the /cgi-bin/param.cgi CGI script, which can lead to remote code execution as root when combined with CVE-2024-8957. This poses a critical risk to DIB organizations relying on PTZOptics hardware for surveillance or access control, as compromised devices could grant attackers full system access. DIB orgs should immediately audit PTZOptics deployments and apply vendor patches or replace hardware until the vulnerability is resolved.

Shame score — The combination of an actively exploited IDOR vulnerability with a separate RCE CVE creates a high-severity supply-chain risk that could lead to unauthorized root access on critical surveillance devices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.