Loading HuntDB...

PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

Added Nov. 4, 2024 Due Nov. 25, 2024 CVE-2024-8957
Overdue PTZOptics / PT30X-SDI/NDI Cameras CWE-78

Description

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.

Required Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 3 weeks ago