CVE-2024-6047 (GCVE-0-2024-6047)
Vulnerability from cvelistv5 – Published: 2024-06-17 05:48 – Updated: 2025-10-21 22:56 Unsupported When Assigned- CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| URL | Tags |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html | third-party-advisory |
| https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html | third-party-advisory |
| https://www.akamai.com/blog/security-research/act… | |
| https://www.cisa.gov/known-exploited-vulnerabilit… | government-resource |
| Vendor | Product | Version | |
|---|---|---|---|
| GeoVision | GV_DSP_LPR_V2 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_BX1500 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_CB220 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_EBL1100 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_EFD1100 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_FD2410 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_FD3400 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_FE3401 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_FE420 |
Affected:
all
|
|
| GeoVision | GV-VS14_VS14 |
Affected:
all
|
|
| GeoVision | GV_VS03 |
Affected:
all
|
|
| GeoVision | GV_VS2410 |
Affected:
all
|
|
| GeoVision | GV_VS28XX |
Affected:
all
|
|
| GeoVision | GV_VS216XX |
Affected:
all
|
|
| GeoVision | GV VS04A |
Affected:
all
|
|
| GeoVision | GV VS04H |
Affected:
all
|
|
| GeoVision | GVLX 4 V2 |
Affected:
all
|
|
| GeoVision | GVLX 4 V3 |
Affected:
all
|
|
| GeoVision | GV_IPCAMD_GV_BX130 |
Affected:
all
|
|
| GeoVision | GV_GM8186_VS14 |
Affected:
all
|
|
| geovision | gv-dsp_lpr_v2 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-dsp_lpr_v2:0:*:*:*:*:*:*:* |
|
| geovision | gv-bx1500 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-bx1500:0:*:*:*:*:*:*:* |
|
| geovision | gv-cb220 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-cb220:0:*:*:*:*:*:*:* |
|
| geovision | gv-ebl1100 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-ebl1100:0:*:*:*:*:*:*:* |
|
| geovision | gv-efd1100 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-efd1100:0:*:*:*:*:*:*:* |
|
| geovision | gv-fd2410 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-fd2410:0:*:*:*:*:*:*:* |
|
| geovision | gv-fd3400 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-fd3400:0:*:*:*:*:*:*:* |
|
| geovision | gv-fd3401 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-fd3401:0:*:*:*:*:*:*:* |
|
| geovision | gv-fe420 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-fe420:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs14 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs14:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs03 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs03:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs2410 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs2410:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs04a |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs04a:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs04h |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs04h:0:*:*:*:*:*:*:* |
|
| geovision | gv-lx_4_v2 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-lx_4_v2:0:*:*:*:*:*:*:* |
|
| geovision | gv-lx_4_v3 |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-lx_4_v3:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs28xx |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs28xx:0:*:*:*:*:*:*:* |
|
| geovision | gv-vs216xx |
Affected:
0 , < *
(custom)
cpe:2.3:h:geovision:gv-vs216xx:0:*:*:*:*:*:*:* |
CISA
Known Exploited Vulnerability - GCVE BCP-07 Compliant
Exploited: Yes
Timestamps
Scope
Evidence
Type: Vendor Report
Signal: Successful Exploitation
Confidence: 80%
Source: cisa-kev
Details
| Cwes | CWE-78 |
|---|---|
| Feed | CISA Known Exploited Vulnerabilities Catalog |
| Product | Multiple Devices |
| Due Date | 2025-05-28 |
| Date Added | 2025-05-07 |
| Vendorproject | GeoVision |
| Vulnerabilityname | GeoVision Devices OS Command Injection Vulnerability |
| Knownransomwarecampaignuse | Unknown |
References
Previdian
Known Exploited Vulnerability - GCVE BCP-07 Compliant
Exploited: Yes
Timestamps
Scope
Evidence
Type: Public Report
Signal: Successful Exploitation
Confidence: 70%
Source: previdian
Details
| Feed | Previdian (previdian.com) |
|---|---|
| Title | GeoVision EOL device - OS Command Injection |
| Cve Id | CVE-2024-6047 |
| Vendor | GeoVision |
| Ghsa Id | None |
| Product | GV_DSP_LPR_V2, GV_IPCAMD_GV_BX1500, GV_IPCAMD_GV_CB220, GV_IPCAMD_GV_EBL1100, GV_IPCAMD_GV_EFD1100, GV_IPCAMD_GV_FD2410, GV_IPCAMD_GV_FD3400, GV_IPCAMD_GV_FE3401, GV_IPCAMD_GV_FE420, GV-VS14_VS14, GV_VS03, GV_VS2410, GV_VS28XX, GV_VS216XX, GV VS04A, GV VS04H, GVLX 4 V2, GVLX 4 V3, GV_IPCAMD_GV_BX130, GV_GM8186_VS14 |
| Added Date | 2025-05-07T06:17:12.242Z |
| Cvss Score | 9.8 |
| Epss Score | 0.10072 |
| Previous Ids | |
| Cvss Severity | CRITICAL |
| Virtual Patch | False |
| Cvss Estimated | False |
| Epss Percentile | 0.95497 |
| Used In Malware | unknown |
| Vulnerability Id | CVE-2024-6047 |
| Ahead Of Cisa Kev |
|
| Not Yet In Cisa Kev | False |
References
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:h:geovision:gv-dsp_lpr_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-dsp_lpr_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-bx1500:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-bx1500",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-cb220:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-cb220",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-ebl1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-ebl1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-efd1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-efd1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3400:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3400",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3401:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3401",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fe420:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fe420",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs14:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs14",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs03:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs03",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04a:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04a",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04h:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04h",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v3:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v3",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs28xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs28xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs216xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs216xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6047",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-07T17:12:10.191958Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2025-05-07",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-10-21T22:56:21.904Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
},
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047"
}
],
"timeline": [
{
"lang": "en",
"time": "2025-05-07T00:00:00.000Z",
"value": "CVE-2024-6047 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:25:03.254Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"third-party-advisory",
"x_transferred"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"tags": [
"third-party-advisory",
"x_transferred"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "GV_DSP_LPR_V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX1500",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_CB220",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EBL1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EFD1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD3400",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE3401",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE420",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV-VS14_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS03",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS28XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS216XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04A",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04H",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V3",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX130",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_GM8186_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
}
],
"datePublic": "2024-06-17T05:48:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
}
],
"value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-17T07:33:54.631Z",
"orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"shortName": "twcert"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "All affected products are no longer in surport. Please retire or replace them."
}
],
"value": "All affected products are no longer in surport. Please retire or replace them."
}
],
"source": {
"advisory": "TVN-202406015",
"discovery": "EXTERNAL"
},
"tags": [
"unsupported-when-assigned"
],
"title": "GeoVision EOL device - OS Command Injection",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"assignerShortName": "twcert",
"cveId": "CVE-2024-6047",
"datePublished": "2024-06-17T05:48:42.779Z",
"dateReserved": "2024-06-17T02:00:24.960Z",
"dateUpdated": "2025-10-21T22:56:21.904Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1",
"vulnerability-lookup:meta": {
"epss": {
"cve": "CVE-2024-6047",
"date": "2026-10-06",
"epss": "0.10072",
"percentile": "0.95513"
},
"nvd": {
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "GV_DSP_LPR_V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX1500",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_CB220",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EBL1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EFD1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD3400",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE3401",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE420",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV-VS14_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS03",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS28XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS216XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04A",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04H",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V3",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX130",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_GM8186_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
}
],
"source": "twcert@cert.org.tw"
},
{
"affectedData": [
{
"cpes": [
"cpe:2.3:h:geovision:gv-dsp_lpr_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-dsp_lpr_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-bx1500:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-bx1500",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-cb220:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-cb220",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-ebl1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-ebl1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-efd1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-efd1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3400:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3400",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3401:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3401",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fe420:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fe420",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs14:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs14",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs03:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs03",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04a:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04a",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04h:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04h",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v3:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v3",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs28xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs28xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs216xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs216xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"cisaActionDue": "2025-05-28",
"cisaExploitAdd": "2025-05-07",
"cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "GeoVision Devices OS Command Injection Vulnerability",
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-dsp_lpr_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8A816357-E53E-45DB-8655-2168D9B81F9F",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-dsp_lpr:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "154516B8-F25A-4426-8EA5-C27E0FB0DEEB",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-bx130_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "446F8D10-A12C-4FA2-A148-556BB1ECA5B6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-bx130:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E7621CA0-FA2B-4ECF-B96A-411644DB87DA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "68B92F9F-99CA-4BCD-B781-FD1FB5154F5F",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-bx1500:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FCB8818D-F869-4882-9EC4-CB7D8C6AEE51",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-cb220_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6534F85F-B545-4560-B162-B3E95709DF3B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-cb220:-:*:*:*:*:*:*:*",
"matchCriteriaId": "94C3B894-2BB6-4343-82B8-37294902CB49",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-ebl1100_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B8E350A2-B008-4856-8967-83C9A2DFCEDD",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-ebl1100:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E9A56C89-54AF-4B47-8704-FD176804DFB0",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-efd1100_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7B5E0CD5-BFF6-42BF-A659-3E46802CF772",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-efd1100:-:*:*:*:*:*:*:*",
"matchCriteriaId": "ECE25C18-DDC4-44AA-8136-0333F1A9AF3A",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-fd2410_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BA607A03-A68E-4555-B568-78C07EBF4F1E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-fd2410:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8CF679AB-22D6-4088-8D59-76EA0849275D",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-fd3400_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "52A580D8-F1AB-4C8A-A457-B584F808425B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-fd3400:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BA723AF9-EDB2-4B97-AC0E-CBD0261D26C1",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-fe3401_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D8CBC909-5C2A-44B7-B100-28310EEAEC98",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-fe3401:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FC695D74-B39B-42D7-9297-F7275A6E6E04",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-fe420_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "92269BD8-FFC5-4674-9ECA-3F051DDE4FE5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-fe420:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CDF27EB0-CE2D-4A27-9001-D9E7F8C62FE6",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-gm8186_vs14_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8C2F6485-845B-4BF3-BC70-B9C757838FBA",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-gm8186_vs14:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C34ABAA2-F4F4-4169-BCDF-BFDF80FF6B97",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs14_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "BDE75E8B-A0EA-4CE7-B1E8-FC9C0755600B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs14:-:*:*:*:*:*:*:*",
"matchCriteriaId": "9B27193C-C8E6-4F0C-8B17-CA251A012CB8",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs03_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5318B9CC-2E05-4A71-9702-24DAD466C276",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs03:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5C52F0B8-B5E8-470B-89CD-B0AF2FA8A7F7",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs2410_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1F20A7EC-F06B-4028-9018-4969B317D302",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs2410:-:*:*:*:*:*:*:*",
"matchCriteriaId": "57E6FC00-F467-49D4-8AD5-A720C66FBE82",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs21600_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "06FC0F74-6AF2-4611-9558-AFEE8873FC65",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs21600:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4E19EB16-16B2-4B51-AB9F-BCDEC0D5ABD0",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs04a_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F67C3872-A119-4555-896B-5FF5669639F1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs04a:-:*:*:*:*:*:*:*",
"matchCriteriaId": "053F1E48-88D7-497F-BE8D-C0FE8C7033D6",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs04h_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D9B0CA1A-C45D-46A8-B8B4-55CE7F1BF041",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs04h:-:*:*:*:*:*:*:*",
"matchCriteriaId": "51106A5E-B449-4614-B6D5-2CF45CE43901",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F102B6E2-FF3F-4A1A-B133-E06567EE6653",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gvlx_4:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "CC0F181D-09E9-43CF-93A5-DA699F4436C5",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:geovision:gvlx_4:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3699699F-80E7-44C8-8564-1448704BCCE0",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs2800_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E531244E-ADB5-4FEC-AB04-5299AD564A21",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs2800:-:*:*:*:*:*:*:*",
"matchCriteriaId": "FABE5E05-324C-4F92-92BF-A50BCACDE046",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:geovision:gv-vs2820_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "DD77D3A8-BA45-4F0C-9A71-E8497026BA34",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:geovision:gv-vs2820:-:*:*:*:*:*:*:*",
"matchCriteriaId": "86FB362A-5752-41E9-ADB8-B711521BA877",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"cveTags": [
{
"sourceIdentifier": "twcert@cert.org.tw",
"tags": [
"unsupported-when-assigned"
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
},
{
"lang": "es",
"value": "Ciertos dispositivos EOL GeoVision no filtran adecuadamente la entrada del usuario para la funcionalidad espec\u00edfica. Los atacantes remotos no autenticados pueden aprovechar esta vulnerabilidad para inyectar y ejecutar comandos arbitrarios del sistema en el dispositivo."
}
],
"id": "CVE-2024-6047",
"lastModified": "2026-06-17T08:17:10.453",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "twcert@cert.org.tw",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-6047",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-07T17:12:10.191958Z",
"version": "2.0.3"
}
}
]
},
"published": "2024-06-17T06:15:09.237",
"references": [
{
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
},
{
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"Exploit",
"Third Party Advisory"
],
"url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"tags": [
"US Government Resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047"
}
],
"sourceIdentifier": "twcert@cert.org.tw",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-78"
}
],
"source": "twcert@cert.org.tw",
"type": "Secondary"
}
]
}
},
"vulnrichment": {
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-01T21:25:03.254Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"third-party-advisory",
"x_transferred"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"tags": [
"third-party-advisory",
"x_transferred"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
}
],
"title": "CVE Program Container"
},
{
"affected": [
{
"cpes": [
"cpe:2.3:h:geovision:gv-dsp_lpr_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-dsp_lpr_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-bx1500:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-bx1500",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-cb220:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-cb220",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-ebl1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-ebl1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-efd1100:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-efd1100",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3400:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3400",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fd3401:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fd3401",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-fe420:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-fe420",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs14:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs14",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs03:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs03",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs2410:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs2410",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04a:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04a",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs04h:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs04h",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v2:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v2",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-lx_4_v3:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-lx_4_v3",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs28xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs28xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:geovision:gv-vs216xx:0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "gv-vs216xx",
"vendor": "geovision",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-6047",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-05-07T17:12:10.191958Z",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2025-05-07",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-17T13:42:38.053Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
},
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047"
}
],
"timeline": [
{
"lang": "en",
"time": "2025-05-07T00:00:00.000Z",
"value": "CVE-2024-6047 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "GV_DSP_LPR_V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX1500",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_CB220",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EBL1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_EFD1100",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FD3400",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE3401",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_FE420",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV-VS14_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS03",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS2410",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS28XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_VS216XX",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04A",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV VS04H",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V2",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GVLX 4 V3",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_IPCAMD_GV_BX130",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
},
{
"defaultStatus": "unaffected",
"product": "GV_GM8186_VS14",
"vendor": "GeoVision",
"versions": [
{
"status": "affected",
"version": "all"
}
]
}
],
"datePublic": "2024-06-17T05:48:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
}
],
"value": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-07-17T07:33:54.631Z",
"orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"shortName": "twcert"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "All affected products are no longer in surport. Please retire or replace them."
}
],
"value": "All affected products are no longer in surport. Please retire or replace them."
}
],
"source": {
"advisory": "TVN-202406015",
"discovery": "EXTERNAL"
},
"tags": [
"unsupported-when-assigned"
],
"title": "GeoVision EOL device - OS Command Injection",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e",
"assignerShortName": "twcert",
"cveId": "CVE-2024-6047",
"datePublished": "2024-06-17T05:48:42.779Z",
"dateReserved": "2024-06-17T02:00:24.960Z",
"dateUpdated": "2025-10-21T22:56:21.904Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
}
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.