TROYANOSYVIRUS
Volver a CVEs

CVE-2024-11120

CRITICALCISA KEV
9.8

Descripcion

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado11/15/2024
Ultima modificacion10/30/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorGeoVision
ProductoMultiple Devices
Nombre vulnerabilidadGeoVision Devices OS Command Injection Vulnerability
Fecha inclusion KEV2025-05-07
Fecha limite remediacion2025-05-28
Uso en ransomwareUnknown

Productos afectados

geovision:gv-dsp_lprgeovision:gv-dsp_lpr_firmwaregeovision:gv-vs11geovision:gv-vs11_firmwaregeovision:gv-vs12geovision:gv-vs12_firmwaregeovision:gvlx_4geovision:gvlx_4_firmware

Debilidades (CWE)

CWE-78

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.