{"id": "CVE-2024-6047", "cveTags": [{"tags": ["unsupported-when-assigned"], "sourceIdentifier": "twcert@cert.org.tw"}], "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "twcert@cert.org.tw", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2024-06-17T06:15:09.237", "references": [{"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html", "tags": ["Third Party Advisory"], "source": "twcert@cert.org.tw"}, {"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html", "tags": ["Third Party Advisory"], "source": "twcert@cert.org.tw"}, {"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet", "tags": ["Exploit", "Third Party Advisory"], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"}, {"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047", "tags": ["US Government Resource"], "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "twcert@cert.org.tw", "description": [{"lang": "en", "value": "CWE-78"}]}], "descriptions": [{"lang": "en", "value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."}, {"lang": "es", "value": "Ciertos dispositivos EOL GeoVision no filtran adecuadamente la entrada del usuario para la funcionalidad espec\u00edfica. Los atacantes remotos no autenticados pueden aprovechar esta vulnerabilidad para inyectar y ejecutar comandos arbitrarios del sistema en el dispositivo."}], "lastModified": "2025-10-30T19:23:34.360", "cisaActionDue": "2025-05-28", "cisaExploitAdd": "2025-05-07", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-dsp_lpr_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A816357-E53E-45DB-8655-2168D9B81F9F"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-dsp_lpr:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "154516B8-F25A-4426-8EA5-C27E0FB0DEEB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-bx130_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "446F8D10-A12C-4FA2-A148-556BB1ECA5B6"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-bx130:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E7621CA0-FA2B-4ECF-B96A-411644DB87DA"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68B92F9F-99CA-4BCD-B781-FD1FB5154F5F"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-bx1500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FCB8818D-F869-4882-9EC4-CB7D8C6AEE51"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-cb220_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6534F85F-B545-4560-B162-B3E95709DF3B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-cb220:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "94C3B894-2BB6-4343-82B8-37294902CB49"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-ebl1100_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8E350A2-B008-4856-8967-83C9A2DFCEDD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-ebl1100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E9A56C89-54AF-4B47-8704-FD176804DFB0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-efd1100_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B5E0CD5-BFF6-42BF-A659-3E46802CF772"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-efd1100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "ECE25C18-DDC4-44AA-8136-0333F1A9AF3A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-fd2410_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA607A03-A68E-4555-B568-78C07EBF4F1E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-fd2410:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8CF679AB-22D6-4088-8D59-76EA0849275D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-fd3400_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52A580D8-F1AB-4C8A-A457-B584F808425B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-fd3400:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "BA723AF9-EDB2-4B97-AC0E-CBD0261D26C1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-fe3401_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8CBC909-5C2A-44B7-B100-28310EEAEC98"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-fe3401:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FC695D74-B39B-42D7-9297-F7275A6E6E04"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-fe420_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92269BD8-FFC5-4674-9ECA-3F051DDE4FE5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-fe420:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CDF27EB0-CE2D-4A27-9001-D9E7F8C62FE6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-gm8186_vs14_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C2F6485-845B-4BF3-BC70-B9C757838FBA"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-gm8186_vs14:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C34ABAA2-F4F4-4169-BCDF-BFDF80FF6B97"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs14_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDE75E8B-A0EA-4CE7-B1E8-FC9C0755600B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs14:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9B27193C-C8E6-4F0C-8B17-CA251A012CB8"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs03_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5318B9CC-2E05-4A71-9702-24DAD466C276"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs03:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5C52F0B8-B5E8-470B-89CD-B0AF2FA8A7F7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs2410_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F20A7EC-F06B-4028-9018-4969B317D302"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs2410:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "57E6FC00-F467-49D4-8AD5-A720C66FBE82"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs21600_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06FC0F74-6AF2-4611-9558-AFEE8873FC65"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs21600:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4E19EB16-16B2-4B51-AB9F-BCDEC0D5ABD0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs04a_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F67C3872-A119-4555-896B-5FF5669639F1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs04a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "053F1E48-88D7-497F-BE8D-C0FE8C7033D6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs04h_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9B0CA1A-C45D-46A8-B8B4-55CE7F1BF041"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs04h:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "51106A5E-B449-4614-B6D5-2CF45CE43901"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F102B6E2-FF3F-4A1A-B133-E06567EE6653"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gvlx_4:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CC0F181D-09E9-43CF-93A5-DA699F4436C5"}, {"criteria": "cpe:2.3:h:geovision:gvlx_4:3.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3699699F-80E7-44C8-8564-1448704BCCE0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs2800_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E531244E-ADB5-4FEC-AB04-5299AD564A21"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs2800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FABE5E05-324C-4F92-92BF-A50BCACDE046"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:geovision:gv-vs2820_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD77D3A8-BA45-4F0C-9A71-E8497026BA34"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:geovision:gv-vs2820:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "86FB362A-5752-41E9-ADB8-B711521BA877"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "twcert@cert.org.tw", "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.", "cisaVulnerabilityName": "GeoVision Devices OS Command Injection Vulnerability"}