← Back to CVE List
Vulnerability Intelligence Report
GeoVision EOL device - OS Command Injection

CVE-2024-6047

unsupported-when-assigned

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:9.99%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
GeoVision GV_DSP_LPR_V2 all (affected)
GeoVision GV_IPCAMD_GV_BX1500 all (affected)
GeoVision GV_IPCAMD_GV_CB220 all (affected)
GeoVision GV_IPCAMD_GV_EBL1100 all (affected)
GeoVision GV_IPCAMD_GV_EFD1100 all (affected)
GeoVision GV_IPCAMD_GV_FD2410 all (affected)
GeoVision GV_IPCAMD_GV_FD3400 all (affected)
GeoVision GV_IPCAMD_GV_FE3401 all (affected)
GeoVision GV_IPCAMD_GV_FE420 all (affected)
GeoVision GV-VS14_VS14 all (affected)
GeoVision GV_VS03 all (affected)
GeoVision GV_VS2410 all (affected)
GeoVision GV_VS28XX all (affected)
GeoVision GV_VS216XX all (affected)
GeoVision GV VS04A all (affected)
GeoVision GV VS04H all (affected)
GeoVision GVLX 4 V2 all (affected)
GeoVision GVLX 4 V3 all (affected)
GeoVision GV_IPCAMD_GV_BX130 all (affected)
GeoVision GV_GM8186_VS14 all (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
9.992%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTWCERT/CC · CERT · Taiwan
Reserved2024-06-17T02:00:24
Published2024-06-17T05:48:42
Patch Date2024-06-17
Last Updated2025-10-21T22:56:21

LINK COPIED TO CLIPBOARD