ZeroHour

CVE-2024-8957

KEV PoC moderate

OS Command Injection in PTZOptics PT30X-SDI/NDI Cameras Enables Chained RCE

CISA: PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
81%p100
Published
()
KEV added
AI analysis

PTZOptics PT30X-SDI and PT30X-NDI-XX-G2 cameras running firmware before 6.3.40 fail to sufficiently validate the ntp_addr configuration value, enabling an OS command injection flaw (CWE-78) that triggers when the camera's ntp_client is started. On its own the flaw requires high-privileged access, consistent with its CVSS 3.1 base score of 7.2, but when chained with CVE-2024-8956 it can be reached by a remote, unauthenticated attacker. Successful exploitation yields arbitrary OS command execution on the camera with high impact to confidentiality, integrity, and availability. Any organization running affected PT30X-series firmware is exposed, with the greatest risk to cameras that are directly reachable from the internet. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-04, indicating in-the-wild exploitation, and a public GreyNoise write-up documents the 0-day RCE alongside an EPSS exploitation probability of 81%.

What to do: Upgrade PT30X-SDI and PT30X-NDI-XX-G2 cameras to firmware 6.3.40 or later per vendor instructions, or apply vendor mitigations or discontinue use per CISA's KEV required action. Audit devices for internet exposure (port forwards, NAT rules, cloud relay access) and restrict management and NTP-related interfaces to trusted networks. Ensure CVE-2024-8956 is also remediated, since chaining it with this bug is what enables unauthenticated remote command execution.

Affected
PTZOptics PT30X-SDI camera firmwareall versions before 6.3.40
PTZOptics PT30X-NDI-XX-G2 camera firmwareall versions before 6.3.40
Estimated exposure
moderatelikely tens of thousands of PT30X-series cameras deployed worldwide, with only a subset (low thousands or fewer) directly internet-exposed — PT30X is a single model line in the niche professional PTZ/live-streaming camera market (broadcast, houses of worship, conference AV) where cameras are typically deployed on internal LANs, so this order-of-magnitude estimate is inferred…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.

CISA Known Exploited Vulnerability
Affected
PTZOptics PT30X-SDI/NDI Cameras
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ptzoptics
Products
pt30x-sdi firmware, pt30x-ndi-xx-g2 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news