← All CVEs

CVE-2024-8956

critical · 9.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2024-11-04Remediation due 2024-11-25

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

9.1
CVSS
61.3%
EPSS (exploit prob.)
99th
EPSS percentile
2024-09-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-306CWE-287

Affected products

VendorProductAffected versions
ptzopticspt30x-sdi_firmware< 6.3.40
ptzopticspt30x-sdiall versions
ptzopticspt30x-ndi-xx-g2_firmware< 6.3.40
ptzopticspt30x-ndi-xx-g2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-8956