PT-2024-7556 · Ptzoptics · Ptzoptics Pt30X-Sdi/Ndi Cameras
Konstantin Lazarev
·
Published
2024-09-17
·
Updated
2025-09-09
·
CVE-2024-8957
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PTZOptics PT30X-SDI/NDI Cameras versions prior to firmware 6.3.40
Description
The issue is related to an OS command injection problem. The camera does not sufficiently validate the
ntp addr configuration value, which may lead to arbitrary command execution when ntp client is started. This can be exploited by a remote and unauthenticated attacker to execute arbitrary OS commands on affected devices. The vulnerability can be exploited by sending a specially crafted request with the ntp addr parameter to the /cgi-bin/param.cgi CGI script.Recommendations
For PTZOptics PT30X-SDI/NDI Cameras versions prior to firmware 6.3.40, update to firmware 6.3.40 or later to resolve the issue. As a temporary workaround, consider restricting access to the
/cgi-bin/param.cgi CGI script and avoiding the use of the ntp addr parameter until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ptzoptics Pt30X-Sdi/Ndi Cameras