OS Command Injection Issue in PTZOptics Cameras
CVE-2024-8957

7.2HIGH

Key Information:

Vendor

Ptzoptics

Vendor
CVE Published:
17 September 2024

Badges

👾 Exploit Exists🟣 EPSS 55%🦅 CISA Reported📰 News Worthy

What is CVE-2024-8957?

The vulnerability arises in PTZOptics PT30X-SDI/NDI-xx models prior to firmware version 6.3.40, where an OS command injection flaw allows attackers to exploit the ntp_addr configuration value. Insufficient validation during the initialization of the ntp_client can lead to the execution of arbitrary OS commands. This vulnerability may be exploited in conjunction with other vulnerabilities, potentially leading to unauthorized access and control over affected devices.

CISA has reported CVE-2024-8957

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-8957 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PT30X-NDI 0 < 6.3.40

PT30X-SDI 0 < 6.3.40

News Articles

CISA Warns of PTZOptics Cameras Vulnerability Exploited to Escalate Privileges

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about critical vulnerabilities identified in PTZOptics PT30X-SDI/NDI cameras.

CVE-2024-8957: Critical Flaw Found In PTZOptics Cameras

Vulnerabilities identified as CVE-2024-8957 and CVE-2024-8956 impact PTZOptics PT30X-SDI/NDI cameras and pose substantial security risks.

PTZOptics cameras zero-days actively exploited in the wild

Hackers are exploiting two zero-day vulnerabilities, tracked as CVE-2024-8956 and CVE-2024-8957, in PTZOptics cameras.

References

EPSS Score

55% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

.