← Browse

CVE-2024-8956

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
61.3%
99.1th percentile
CISA KEV
Listed
Added 2024-11-04 · patch by 2024-11-25
Weakness / dates
Published — · modified —

Description

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

Official: NVD · CVE.org