← All CVEs

CVE-2024-8957

high · 7.2Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2024-11-04Remediation due 2024-11-25

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.

7.2
CVSS
81.0%
EPSS (exploit prob.)
100th
EPSS percentile
2024-09-17
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
ptzopticspt30x-sdi_firmware< 6.3.40
ptzopticspt30x-sdiall versions
ptzopticspt30x-ndi-xx-g2_firmware< 6.3.40
ptzopticspt30x-ndi-xx-g2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-8957