Skip to content
COOEY

EXPOSURES › CVE-2024-8957

CVE-2024-8957

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-8957 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

PTZOptics PT30X-SDI/NDI cameras allow authenticated attackers to escalate to root via OS command injection in the ntp_addr parameter.

This vulnerability enables privilege escalation to root on PTZOptics PT30X-SDI/NDI cameras, allowing remote attackers to execute arbitrary OS commands. DIB organizations must immediately patch these devices to prevent unauthorized access to camera management systems and potential lateral movement into secure networks.

Shame score — The vulnerability allows authenticated attackers to escalate privileges to root, representing a significant security risk for DIB organizations using these cameras.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.