CRITICAL

CVE-2024-6047

Geovision Gv Dsp Lpr Firmware 2024-06-17 CVSS v3.1
CVSS
9.8
KEV

Description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

Summary dbcve.org

A command injection vulnerability in GeoVision end-of-life devices allows unauthenticated remote attackers to execute arbitrary system commands due to improper user input filtering in specific device functionality.

Mitigation

Since GeoVision EOL devices will not receive security patches, immediately retire and replace affected devices, or at minimum isolate them from untrusted networks using firewall rules to restrict access to trusted IPs only.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

10.07%
Probability of exploitation in next 30 days
95.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE