CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2024-8957

🔥 Known Exploited (CISA KEV)HIGH
7.2
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-09-17
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices.

Affected Platforms (CPE)

💻
Ptzoptics

Pt30x Sdi Firmware

< 6.3.40
💻
Ptzoptics

Pt30x Ndi Xx G2 Firmware

< 6.3.40

References & Advisories

相關漏洞威脅