CVE-2024-8956
critical · 9.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ptzoptics | pt30x-sdi_firmware | < 6.3.40 |
| ptzoptics | pt30x-sdi | all versions |
| ptzoptics | pt30x-ndi-xx-g2_firmware | < 6.3.40 |
| ptzoptics | pt30x-ndi-xx-g2 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://ptzoptics.com/firmware-changelog/
- https://vulncheck.com/advisories/ptzoptics-insufficient-auth
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8956
- https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-8956