← العودة للجدول
CVE-2024-8956
PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability — KEV
📅 2024-11-04
🔴 Critical 🔥 Yes CISA KEV ICS/OT OT/ICS 🎯 EPSS 83.61%

📋 الوصف الكامل

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root. | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

💻 الأنظمة المتأثرة

PTZOptics PT30X-SDI/NDI Cameras

⚠️ نوع التهديد

ICS/OT

🔗 CVE ID

CVE-2024-8956

📡 المصدر

CISA KEV

✅ الحلول والتخفيف

Apply patch by 2024-11-25

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←