CVE-2024-8956
PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 November 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 61.28% probability · 99th percentile
- CISA KEV
- Listed 4 November 2024 · due 25 November 2024
- Weakness
- CWE-306, CWE-287
- Affected
- ptzoptics/pt30x-sdi firmware · ptzoptics/pt30x-ndi-xx-g2 firmware
- Source
- disclosure@vulncheck.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://ptzoptics.com/firmware-changelog/ ; https://nvd.nist.gov/vuln/detail/CVE-2024-8956
References
- https://ptzoptics.com/firmware-changelog/Release Notes
- https://vulncheck.com/advisories/ptzoptics-insufficient-authThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8956US Government Resource
- https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-aiThird Party Advisory
- https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.