CVE-2024-8957
KEV PoC moderateOS Command Injection in PTZOptics PT30X-SDI/NDI Cameras Enables Chained RCE
CISA: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability
PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras running firmware before 6.3.40 fail to sufficiently validate the ntp_addr configuration value, enabling an OS command injection flaw (CWE-78) that triggers when the camera's ntp_client is started. On its own the flaw requires high-privileged access, consistent with its CVSS 3.1 base score of 7.2, but when chained with CVE-2024-8956 it can be reached by a remote, unauthenticated attacker. Successful exploitation yields arbitrary OS command execution on the camera with high impact to confidentiality, integrity, and availability. Any organization running affected PT30X-series firmware is exposed, with the greatest risk to cameras that are directly reachable from the internet. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-04, indicating in-the-wild exploitation, and a public GreyNoise write-up documents the 0-day RCE alongside an EPSS exploitation probability of 81%.
What to do: Upgrade PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later per vendor instructions, or apply vendor mitigations or discontinue use per CISA's KEV required action. Audit devices for internet exposure (port forwards, NAT rules, cloud relay access) and restrict management and NTP-related interfaces to trusted networks. Ensure CVE-2024-8956 is also remediated, since chaining it with this bug is what enables unauthenticated remote command execution.
| PTZOptics PT30X-SDI camera firmware | all versions before 6.3.40 |
| PTZOptics PT30X-NDI-XX-G2 camera firmware | all versions before 6.3.40 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.
- Affected
- PTZOptics PT30X-SDI/NDI Cameras
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- ptzoptics
- Products
- pt30x-sdi firmware, pt30x-ndi-xx-g2 firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H