Insufficient Authentication Vulnerability in PTZOptics PT30X-SDI/NDI-xx Before Firmware 6.3.40
CVE-2024-8956

9.1CRITICAL

Key Information:

Vendor

Ptzoptics

Vendor
CVE Published:
17 September 2024

Badges

👾 Exploit Exists🟣 EPSS 83%🦅 CISA Reported📰 News Worthy

What is CVE-2024-8956?

CVE-2024-8956 and CVE-2024-8957 are zero-day vulnerabilities in PTZOptics pan-tilt-zoom (PTZ) live streaming cameras, allowing attackers to access sensitive data, execute remote code, and take over the camera. The vulnerabilities impact NDI-enabled cameras based on Hisilicon Hi3516A V600 SoC V60, V61, and V63, running VHD PTZ camera firmware versions older than 6.3.40. PTZOptics released a security update for some models but has not fixed others, leaving a broad range of devices potentially affected. The exploitation of these flaws could lead to complete camera takeover, infection with bots, pivoting to other devices connected to the same network, or disruption of video feeds. No known exploitation by ransomware groups has been reported at this time.

CISA has reported CVE-2024-8956

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-8956 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PT30X-NDI 0 < 6.3.40

PT30X-SDI 0 < 6.3.40

News Articles

CISA Warns of PTZOptics Cameras Vulnerability Exploited to Escalate Privileges

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about critical vulnerabilities identified in PTZOptics PT30X-SDI/NDI cameras.

PTZOptics cameras zero-days actively exploited in the wild

Hackers are exploiting two zero-day vulnerabilities, tracked as CVE-2024-8956 and CVE-2024-8957, in PTZOptics cameras.

GreyNoise Credits AI for Spotting Exploit Attempts on IoT Livestream Cams

GreyNoise Intelligence says an internal AI tool captured attempts to exploit critical vulnerabilities in commercial livestream IoT cameras.

References

EPSS Score

83% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🦅

    CISA Reported

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

.