SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-6047

GeoVision Devices OS Command Injection Vulnerability

KEVCRITICAL 9.8EPSS 10.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 May 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
10.07% probability · 95th percentile
CISA KEV
Listed 7 May 2025 · due 28 May 2025
Weakness
CWE-78
Affected
geovision/gv-dsp lpr firmware · geovision/gv-bx130 firmware · geovision/gv-bx1500 firmware · geovision/gv-cb220 firmware · geovision/gv-ebl1100 firmware · geovision/gv-efd1100 firmware · geovision/gv-fd2410 firmware · geovision/gv-fd3400 firmware · geovision/gv-fe3401 firmware · geovision/gv-fe420 firmware · geovision/gv-gm8186 vs14 firmware · geovision/gv-vs14 firmware · geovision/gv-vs03 firmware · geovision/gv-vs2410 firmware · geovision/gv-vs21600 firmware · geovision/gv-vs04a firmware · geovision/gv-vs04h firmware · geovision/gvlx 4 firmware · geovision/gv-vs2800 firmware · geovision/gv-vs2820 firmware
Source
twcert@cert.org.tw

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://dlcdn.geovision.com.tw/TechNotice/CyberSecurity/Security_Advisory_IP_Device_2024-11.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2024-6047

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.