ZeroHour

CVE-2024-8956

KEV PoC niche

Authentication Bypass in PTZOptics PT30X-SDI/NDI Cameras Leaks Credentials

CISA: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

CVSS 3.1
9.1 critical
EPSS
61%p99
Published
()
KEV added
AI analysis

PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras fail to enforce authentication on the /cgi-bin/param.cgi endpoint when HTTP requests omit the Authorization header. By sending crafted requests without that header, a remote unauthenticated attacker can read sensitive data including usernames, password hashes, and configuration details, and can modify individual configuration values or overwrite the entire configuration file. Any PTZOptics PT30X-SDI or PT30X-NDI-XX-G2 camera running firmware prior to 6.3.40 is affected, particularly units reachable from untrusted networks. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-04, and a public PoC reference from GreyNoise (2024-10-31) describes it as a zero-day being exploited. With an EPSS of 61.3% (99th percentile), widespread opportunistic exploitation is expected in the coming weeks.

What to do: Upgrade affected PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later as required by CISA's KEV listing. Until patched, restrict HTTP access to the cameras with firewall/ACL rules and avoid exposing the web interface to the internet. Check camera configuration for unexpected changes, and rotate camera credentials since usernames and password hashes may have been disclosed.

Affected
PTZOptics PT30X-SDI camera firmwareAll versions before 6.3.40
PTZOptics PT30X-NDI-XX-G2 camera firmwareAll versions before 6.3.40
Estimated exposure
nichelikely low thousands of internet-exposed units, with an unknown total installed base — PT30X-series PTZ cameras are specialized pro-AV/streaming devices typically deployed on LANs behind NAT, and only a fraction of the installed base is exposed to the internet per public scan patterns for similar camera-class devices, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.

CISA Known Exploited Vulnerability
Affected
PTZOptics PT30X-SDI/NDI Cameras
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ptzoptics
Products
pt30x-sdi firmware, pt30x-ndi-xx-g2 firmware
Weakness
CWE-306, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news