Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Geovision
Geovision gv-dsp Lpr V3 Firmware Geovision gv-vs11 Firmware Geovision gv-vs12 Firmware Geovision gvlx 4 V2 Firmware Geovision gvlx 4 V3 Firmware |
|
CPEs | cpe:2.3:o:geovision:gv-dsp_lpr_v3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:geovision:gv-vs11_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:geovision:gv-vs12_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:geovision:gvlx_4_v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:geovision:gvlx_4_v3_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Geovision
Geovision gv-dsp Lpr V3 Firmware Geovision gv-vs11 Firmware Geovision gv-vs12 Firmware Geovision gvlx 4 V2 Firmware Geovision gvlx 4 V3 Firmware |
|
Metrics |
ssvc
|
Fri, 15 Nov 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports. | |
Title | GeoVision EOL devices - OS Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-11-15T02:00:27.361Z
Updated: 2024-11-15T19:39:22.203Z
Reserved: 2024-11-12T06:23:33.571Z
Link: CVE-2024-11120
Vulnrichment
Updated: 2024-11-15T19:39:06.804Z
NVD
Status : Awaiting Analysis
Published: 2024-11-15T02:15:17.757
Modified: 2024-11-15T13:58:08.913
Link: CVE-2024-11120
Redhat
No data.