CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-8957

Critical Severity
87
SVRS
7.2
CVSSv3
0.81973
EPSS
TAGS
In The WildCISA KEVExploit Avaliable
VECTOR STRING
CVSS:3.1AV:NAC:LPR:HUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-09-17
LAST MODIFIED2025-12-27

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-8957, is an OS command injection issue (CWE-78) affecting PTZOptics PT30X-SDI/NDI-xx cameras. It matters significantly because it allows for arbitrary OS command execution on affected devices. When chained with CVE-2024-8956, this vulnerability can be exploited by a remote and unauthenticated attacker, giving them complete control over the compromised camera. The ability to execute arbitrary commands without authentication presents a critical security risk, potentially leading to unauthorized surveillance, denial of service, or further network penetration.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for CVE-2024-8957 is 7.2, which classifies its severity level as High. The vulnerability was publicly disclosed and published on 2024-09-17 20:08:25 UTC. The CVE details were last modified on 2025-12-27 16:47:39 UTC.
3. Which products, vendors, systems, and versions are affected?
  • Vendor: PTZOptics
  • Products: PTZOptics PT30X-SDI/NDI-xx series cameras
  • Affected Versions: All firmware versions prior to 6.3.40
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is insufficient validation of the ntp_addr configuration value within the camera's firmware. The system fails to properly sanitize or validate user-supplied input for the NTP address, allowing malicious commands to be embedded within this configuration. The attack vector involves exploiting this lack of validation, leading to arbitrary command execution when the ntp_client service is started. Specifically, a remote and unauthenticated attacker can leverage this flaw, particularly when chained with CVE-2024-8956, to inject and execute OS commands.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker injecting arbitrary OS commands into the ntp_addr configuration value. When the ntp_client service on the PTZOptics camera is initiated or restarted, it will attempt to process this malformed NTP address, consequently executing the embedded commands. The description indicates that when this vulnerability (CVE-2024-8957) is chained with CVE-2024-8956, it enables a remote and unauthenticated attacker to successfully achieve arbitrary OS command execution on the affected devices.
6. What mitigation steps and patches are available?
The primary mitigation step for this vulnerability is to update the camera's firmware. Users should upgrade their PTZOptics PT30X-SDI/NDI-xx cameras to firmware version 6.3.40 or a later, patched version. This updated firmware addresses the insufficient validation issue related to the ntp_addr configuration value.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the installed firmware version on PTZOptics PT30X-SDI/NDI-xx cameras. Any device running a firmware version older than 6.3.40 is considered vulnerable to CVE-2024-8957. Administrators should access the camera's administrative interface or utilize appropriate management tools to verify the current firmware version.
8. What are the indicators of compromise (IOCs)?
While specific IOCs directly from the CVE data are not provided, an OS command injection leading to arbitrary execution could manifest through the following general indicators:
  • Unusual or unauthorized processes running on the camera's operating system.
  • Unexpected outgoing network connections from the camera to unknown external IP addresses.
  • Changes to the camera's configuration that were not initiated by an administrator.
  • Presence of unusual files or directories on the camera's file system.
  • Spikes in CPU or memory usage not attributable to normal camera operations.
9. Which threat actors are known to exploit this vulnerability?
The CVE data indicates that "Active exploits have been published to exploit the vulnerability," suggesting that threat actors are actively leveraging this flaw. However, the specific identities or affiliations of these threat actors are not detailed in the provided information.
10. What public intelligence references and advisories exist?
  • CVE-2024-8957: This is the primary public reference detailing the OS command injection vulnerability.
  • CVE-2024-8956: This related CVE is mentioned as a vulnerability that, when chained with CVE-2024-8957, facilitates remote and unauthenticated arbitrary OS command execution.
Further intelligence and advisories would typically be found through official vendor security bulletins (PTZOptics), national CERTs, and cybersecurity research outlets.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-8957 is High, as indicated by its CVSS score of 7.2. The vulnerability allows for arbitrary OS command execution, which can lead to complete compromise of the affected device. The urgency level is also High, especially given that active exploits have been published, and it can be exploited by remote and unauthenticated attackers when chained with CVE-2024-8956. Immediate patching to firmware version 6.3.40 or newer is strongly recommended to prevent potential exploitation and mitigate severe security risks.

No IOCs found for this CVE

TitleSoftware LinkDate
PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-89572024-11-04
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE-2024-8957 | PTZOptics PT30X-SDI/PT30X-NDI up to 6.3.39 ntp_addr os command injection (EUVD-2024-49506 / Nessus ID 210334)
vuldb.com2025-11-22
CVE-2024-8957 | PTZOptics PT30X-SDI/PT30X-NDI up to 6.3.39 ntp_addr os command injection (EUVD-2024-49506 / Nessus ID 210334) | A vulnerability identified as critical has been detected in PTZOptics PT30X-SDI and PT30X-NDI up to 6.3.39. This vulnerability affects unknown code. Performing manipulation of the argument ntp_addr results in os command injection. This vulnerability is reported as CVE-2024-8957
vuldb.comrssforumnews
CVE-2024-8957 | PTZOptics PT30X-SDI/PT30X-NDI up to 6.3.39 ntp_addr os command injection (Nessus ID 210334)
vuldb.com2025-09-09
CVE-2024-8957 | PTZOptics PT30X-SDI/PT30X-NDI up to 6.3.39 ntp_addr os command injection (Nessus ID 210334) | A vulnerability identified as critical has been detected in PTZOptics PT30X-SDI and PT30X-NDI up to 6.3.39. This vulnerability affects unknown code. Performing manipulation of the argument ntp_addr results in os command injection. This vulnerability is reported as CVE-2024-8957. The attack is
vuldb.comrssforumnews

No tweets found for this CVE

No affected software found for this CVE

ReferenceLink
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
[email protected]https://ptzoptics.com/firmware-changelog/
[email protected]https://vulncheck.com/advisories/ptzoptics-command-injection
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
[email protected]https://ptzoptics.com/firmware-changelog/
[email protected]https://ptzoptics.com/firmware-changelog/
[email protected]https://vulncheck.com/advisories/ptzoptics-command-injection
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.greynoise.io/blog/greynoise-intelligence-discovers-zero-day-vulnerabilities-in-live-streaming-cameras-with-the-help-of-ai
134C704F-9B21-4F2E-91B3-4A467353BCC0https://www.labs.greynoise.io/grimoire/2024-10-31-sift-0-day-rce/
[email protected]https://ptzoptics.com/firmware-changelog/
[email protected]https://vulncheck.com/advisories/ptzoptics-command-injection
CWE IDCWE NameDescription
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')The software constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.