ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-6047CVE-2024-11120

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-11120
Unauthenticated OS Command Injection in GeoVision Devices

Multiple GeoVision devices contain an unauthenticated OS command injection flaw (CWE-78) that allows a remote attacker to inject and execute arbitrary system commands on the device. Because no authentication is required, any party that can reach an affected device's network services can trigger the flaw with crafted input; no public proof-of-concept is known. Successful exploitation gives the attacker remote command execution on the device, which can be used to compromise surveillance infrastructure or pivot into connected networks. Organizations running GeoVision devices are affected, and CISA notes the impacted products may be end-of-life (EoL) and/or end-of-service (EoS), meaning some may no longer receive fixes. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-07, confirming exploitation in the wild; EPSS estimates a 28.4% probability of exploitation in the next 30 days (98th percentile), and ransomware use is not yet confirmed.

Do: Inventory all GeoVision devices (including EoL/EoS models) and consult the vendor advisory for affected models and any available firmware mitigations or patches. Restrict internet exposure of GeoVision devices while remediating (firewall rules/ACLs, remove direct port forwarding), and replace or retire EoL/EoS units if the vendor offers no mitigation. Because the flaw is confirmed exploited in the wild, check devices for signs of compromise and unusual outbound traffic.

9.828% KEV PoC
  • GeoVision
largeon the order of tens of thousands of internet-exposed GeoVision devices, with a larger legacy installed base
CVE-2024-6047
Unauthenticated OS Command Injection in End-of-Life GeoVision Devices

CVE-2024-6047 is an unauthenticated OS command injection flaw (CWE-78) in certain end-of-life GeoVision surveillance devices, which fail to properly filter user input for a specific functionality. A remote attacker can trigger it by sending crafted input to the affected device over the network with no authentication required, causing arbitrary system commands to be injected and executed on the device. Successful exploitation grants attackers control of the device, which has been leveraged to recruit GeoVision units into Mirai botnets. Organizations still running the listed EOL GeoVision devices (e.g., GV-BX, GV-CB, GV-EBL, GV-EFD, GV-FD, GV-FE series devices, GV-DSP LPR units, and GV-VS14/GV-GM8186 VS14 units) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-07, Akamai has documented active Mirai-based exploitation, and EPSS puts the 30-day exploitation probability at about 10%.

Do: Inventory internet-facing GeoVision devices, identify the listed EOL models, and apply mitigations per vendor instructions (e.g., restrict web/management access to trusted networks) or discontinue use and replace the devices if mitigations are unavailable, since the affected devices are end-of-life. US federal agencies must remediate per BOD 22-01 following the KEV listing. Given active Mirai botnet exploitation and ~10% EPSS, prioritize devices exposed to the internet and check for anomalous outbound traffic consistent with botnet activity.

9.810% KEV PoC
  • GeoVision GV-DSP LPR firmware End-of-life firmware; all versions, no fixed release listed in available data
  • GeoVision GV-BX130 firmware End-of-life firmware; all versions, no fixed release listed in available data
  • GeoVision GV-BX1500 firmware End-of-life firmware; all versions, no fixed release listed in available data
  • +9 more
largeLikely tens of thousands of internet-exposed GeoVision devices (order of magnitude 10k–100k); exact count unknown
Full article398 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GoVision device flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2024-6047 (CVSS score 9.8) GeoVision Devices OS Command Injection Vulnerability. Multiple EOL GeoVision devices fail to properly filter user input for the specific functionality. An unauthenticated remote attacker can exploit the CVE-2024-6047 vulnerability to inject and execute arbitrary system commands on the device.
  • CVE-2024-11120 (CVSS score 9.8) GeoVision Devices OS Command Injection Vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject and execute arbitrary system commands on the device. The vulnerability has already been exploited by attackers in the wild. In November 2024, researchers at the Shadowserver Foundation observed a botnet exploiting the zero-day flaw CVE-2024-11120 in GeoVision EOL (end-of-Life) devices to compromise devices in the wild. The GeoVision zero-day CVE-2024-11120 (CVSS 9.8) is a pre-auth command injection vulnerability that was discovered by Shadowserver Foundation and verified with the help of TWCERT. The vulnerability impacts the following EoL products: GV-VS12, GV-VS11, GV-DSP_LPR_V3, GVLX 4 V2, GVLX 4 V3. “Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.” reads the advisory published by TWCERT. “Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.” The botnet was used to carry out DDoS or cryptomining attacks. According to Shadowserver Foundation, there were approximately 17,000 Internet-facing GeoVision devices vulnerable to the CVE-2024-11120 zero-day. Unfortunately, the number of Internet-facing GeoVision devices vulnerable to the CVE-2024-11120 zero-day, is still high. Most of the exposed devices are based in the United States (8,720), followed by Germany (1,518), Taiwan (789), and Canada (761).

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by May 28, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/177599/security/u-s-cisa-adds-govision-device-flaws-to-its-known-exploited-vulnerabilities-catalog.html