Ptzoptics Pt30X-Ndi-Xx-G2 Firmware vulnerabilities
2 known vulnerabilities affecting ptzoptics/pt30x-ndi-xx-g2_firmware.
Total CVEs
2
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2024-8957P1HIGHCVSS 7.2KEVRansomwarefixed in 6.3.402024-09-17
CVE-2024-8957 [HIGH] CVE-2024-8957: PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. Th
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected
nvd
CVE-2024-8956P1CRITICALCVSS 9.1KEVfixed in 6.3.402024-09-17
CVE-2024-8956 [CRITICAL] CWE-306 CVE-2024-8956: PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication is
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes,
nvd