CVE-2024-6047

Confirmed PUBLISHED

GeoVision EOL device - OS Command Injection

GeoVision · GV_DSP_LPR_V2, GV_IPCAMD_GV_BX1500, GV_IPCAMD_GV_CB220, GV_IPCAMD_GV_EBL1100, GV_IPCAMD_GV_EFD1100, GV_IPCAMD_GV_FD2410, GV_IPCAMD_GV_FD3400, GV_IPCAMD_GV_FE3401, GV_IPCAMD_GV_FE420, GV-VS14_VS14, GV_VS03, GV_VS2410, GV_VS28XX, GV_VS216XX, GV VS04A, GV VS04H, GVLX 4 V2, GVLX 4 V3, GV_IPCAMD_GV_BX130, GV_GM8186_VS14

391 days faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 10.0%

At a Glance

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

cisa
CVE Published
Jun 17, 2024
Exploitation Reported
May 07, 2025
CVSS
9.8 Critical
EPSS
10.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

38 version rows · page 2 of 2

Vendor Product Version Status
GeoVision
GV_IPCAMD_GV_FE3401

all

Affected
GeoVision
GV_IPCAMD_GV_FE420

all

Affected
GeoVision
GV-VS14_VS14

all

Affected
GeoVision
GV_VS03

all

Affected
GeoVision
GV_VS2410

all

Affected
GeoVision
GV_VS28XX

all

Affected
GeoVision
GV_VS216XX

all

Affected
GeoVision
GV VS04A

all

Affected
GeoVision
GV VS04H

all

Affected
GeoVision
GVLX 4 V2

all

Affected
GeoVision
GVLX 4 V3

all

Affected
GeoVision
GV_IPCAMD_GV_BX130

all

Affected
GeoVision
GV_GM8186_VS14

all

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.