EXPOSURES › CVE-2024-8956
CVE-2024-8956
HIGH ⌖ ON CISA KEV · EXPLOITEDPTZOptics PT30X-SDI/NDI cameras allow remote authentication bypass via IDOR, enabling root RCE when combined with CVE-2024-8957.
PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that bypasses authentication for the /cgi-bin/param.cgi CGI script, which can lead to remote code execution as root when combined with CVE-2024-8957. This poses a critical risk to DIB organizations relying on PTZOptics hardware for surveillance or access control, as compromised devices could grant attackers full system access. DIB orgs should immediately audit PTZOptics deployments and apply vendor patches or replace hardware until the vulnerability is resolved.
Shame score — The combination of an actively exploited IDOR vulnerability with a separate RCE CVE creates a high-severity supply-chain risk that could lead to unauthorized root access on critical surveillance devices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.