OS Command Injection Issue in PTZOptics Cameras
CVE-2024-8957
Key Information:
Badges
What is CVE-2024-8957?
The vulnerability arises in PTZOptics PT30X-SDI/NDI-xx models prior to firmware version 6.3.40, where an OS command injection flaw allows attackers to exploit the ntp_addr configuration value. Insufficient validation during the initialization of the ntp_client can lead to the execution of arbitrary OS commands. This vulnerability may be exploited in conjunction with other vulnerabilities, potentially leading to unauthorized access and control over affected devices.
CISA has reported CVE-2024-8957
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-8957 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PT30X-NDI 0 < 6.3.40
PT30X-SDI 0 < 6.3.40
News Articles
CISA Warns of PTZOptics Cameras Vulnerability Exploited to Escalate Privileges
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about critical vulnerabilities identified in PTZOptics PT30X-SDI/NDI cameras.
CVE-2024-8957: Critical Flaw Found In PTZOptics Cameras
Vulnerabilities identified as CVE-2024-8957 and CVE-2024-8956 impact PTZOptics PT30X-SDI/NDI cameras and pose substantial security risks.
PTZOptics cameras zero-days actively exploited in the wild
Hackers are exploiting two zero-day vulnerabilities, tracked as CVE-2024-8956 and CVE-2024-8957, in PTZOptics cameras.
References
EPSS Score
55% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by BleepingComputer
Vulnerability published
