#VU99607 OS Command Injection in PT30X-SDI/NDI-xx - CVE-2024-8957
Published: November 1, 2024
PT30X-SDI/NDI-xx
PTZOptics
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when handling the ntp_addr configuration value. A remote user can set a specially crafted value in the configuration file and execute arbitrary OS commands on the system.
Note, this vulnerability can be also exploited by an unauthenticated attacker if chained with #VU99606 (CVE-2024-8956).