← Back to CVE List
Vulnerability Intelligence Report
PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration

CVE-2024-8957

x_known-exploited-vulnerability

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:81.97%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
PTZOptics PT30X-SDI 0 < 6.3.40 (affected)
PTZOptics PT30X-NDI 0 < 6.3.40 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
81.973%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2024-09-17T19:08:48
Published2024-09-17T20:08:25
Last Updated2025-12-27T16:47:39

LINK COPIED TO CLIPBOARD