CVE-2024-6047

CRITICALCVSS 9.8/10Actively ExploitedEPSS 9.99%

Last modified

CVE-2024-6047 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.. CISA has confirmed active exploitation in the wild. EPSS estimates a 9.99% chance of exploitation in the next 30 days.

Description

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
9.99%

95.0th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
GeovisionGv-Dsp Lpr FirmwareAll versions
GeovisionGv-Bx130 FirmwareAll versions
GeovisionGv-Bx1500 FirmwareAll versions
GeovisionGv-Cb220 FirmwareAll versions
GeovisionGv-Ebl1100 FirmwareAll versions
GeovisionGv-Efd1100 FirmwareAll versions
GeovisionGv-Fd2410 FirmwareAll versions
GeovisionGv-Fd3400 FirmwareAll versions
GeovisionGv-Fe3401 FirmwareAll versions
GeovisionGv-Fe420 FirmwareAll versions
GeovisionGv-Gm8186 Vs14 FirmwareAll versions
GeovisionGv-Vs14 FirmwareAll versions
GeovisionGv-Vs03 FirmwareAll versions
GeovisionGv-Vs2410 FirmwareAll versions
GeovisionGv-Vs21600 FirmwareAll versions
GeovisionGv-Vs04a FirmwareAll versions
GeovisionGv-Vs04h FirmwareAll versions
GeovisionGvlx 4 FirmwareAll versions
GeovisionGv-Vs2800 FirmwareAll versions
GeovisionGv-Vs2820 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-6047?
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
How severe is CVE-2024-6047?
CVE-2024-6047 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 9.99% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2024-6047?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-6047?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST