CVE-2024-8956
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
61.3%
99.1th percentile
CISA KEV
Listed
Added 2024-11-04 · patch by 2024-11-25
Weakness / dates
—
Published — · modified —
Description
PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.