CRITICAL

CVE-2024-11120

Geovision Gv Vs12 Firmware 2024-11-15 CVSS v3.1
CVSS
9.8
KEV

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Summary dbcve.org

OS command injection vulnerability in EOL GeoVision devices allowing unauthenticated remote attackers to inject and execute arbitrary system commands. Actively exploited in the wild.

Mitigation

Since GeoVision devices are End-of-Life with no patch available, immediately isolate affected devices from the internet, place them behind network segmentation, and consider replacement with supported hardware. Implement additional monitoring for Indicators of Compromise.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

28.39%
Probability of exploitation in next 30 days
98.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE