CVE-2024-8956
KEV PoC nicheAuthentication Bypass in PTZOptics PT30X-SDI/NDI Cameras Leaks Credentials
CISA: PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability
PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras fail to enforce authentication on the /cgi-bin/param.cgi endpoint when HTTP requests omit the Authorization header. By sending crafted requests without that header, a remote unauthenticated attacker can read sensitive data including usernames, password hashes, and configuration details, and can modify individual configuration values or overwrite the entire configuration file. Any PTZOptics PT30X-SDI or PT30X-NDI-XX-G2 camera running firmware prior to 6.3.40 is affected, particularly units reachable from untrusted networks. The flaw is confirmed to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-04, and a public PoC reference from GreyNoise (2024-10-31) describes it as a zero-day being exploited. With an EPSS of 61.3% (99th percentile), widespread opportunistic exploitation is expected in the coming weeks.
What to do: Upgrade affected PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later as required by CISA's KEV listing. Until patched, restrict HTTP access to the cameras with firewall/ACL rules and avoid exposing the web interface to the internet. Check camera configuration for unexpected changes, and rotate camera credentials since usernames and password hashes may have been disclosed.
| PTZOptics PT30X-SDI camera firmware | All versions before 6.3.40 |
| PTZOptics PT30X-NDI-XX-G2 camera firmware | All versions before 6.3.40 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
- Affected
- PTZOptics PT30X-SDI/NDI Cameras
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ptzoptics
- Products
- pt30x-sdi firmware, pt30x-ndi-xx-g2 firmware
- Weakness
- CWE-306, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N