CVE-2024-6047
GeoVision · Published June 17, 2024
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
Affected Products
- GV DSP LPR Firmware
- GV Bx130 Firmware
- GV Bx1500 Firmware
- GV Cb220 Firmware
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H