CRITICAL
CVE-2024-6047
CVSS
9.8
KEV
Description
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
Summary dbcve.org
A command injection vulnerability in GeoVision end-of-life devices allows unauthenticated remote attackers to execute arbitrary system commands due to improper user input filtering in specific device functionality.
Mitigation
Since GeoVision EOL devices will not receive security patches, immediately retire and replace affected devices, or at minimum isolate them from untrusted networks using firewall rules to restrict access to trusted IPs only.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
10.07%
Probability of exploitation in next 30 days
95.5th percentile
References
https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html
Third Party Advisory
https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.