CVE-2024-8956 Details
Description
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-8956 | CISA-ADP | US Government Resource |
| https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai | CISA-ADP | Third Party Advisory |
| https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/ | CISA-ADP | ExploitThird Party Advisory |
| https://ptzoptics.com/firmware-changelog/ | [email protected] | Release Notes |
| https://vulncheck.com/advisories/ptzoptics-insufficient-auth | [email protected] | Third Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability | Nov 4, 2024 | Nov 25, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ptzoptics pt30x-sdi firmware | < 6.3.40 |
CPE
Remediation
| |
| ptzoptics pt30x-sdi | All versions |
CPE
Remediation
| |
| ptzoptics pt30x-ndi-xx-g2 firmware | < 6.3.40 |
CPE
Remediation
| |
| ptzoptics pt30x-ndi-xx-g2 | All versions |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Sep 26, 2025 | Modified Analysis | [email protected] |
| Sep 25, 2025 | CVE Modified | [email protected] |
| Sep 9, 2025 | Modified Analysis | [email protected] |
| Sep 8, 2025 | CVE Modified | CISA-ADP |
| Nov 5, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Oct 1, 2024 | Initial Analysis | [email protected] |
| Sep 17, 2024 | New CVE Received | [email protected] |