GeoVision Vulnerabilities and Affected Products
Vulnerabilities associated with GVLX 4 V2.
Products
Clear product- Door Access Control Device4 vulnerabilities
- GVLX 4 V22 vulnerabilities
- GVLX 4 V32 vulnerabilities
- Multiple Devices2 vulnerabilities
- GeoVision Geowebserver1 vulnerability
- GeoWebServer1 vulnerability
- GV VS04A1 vulnerability
- GV VS04H1 vulnerability
- GV-ADR27011 vulnerability
- GV-ASManager1 vulnerability
- gv-bx15001 vulnerability
- GV-BX1500/GV-MFD15011 vulnerability
- gv-cb2201 vulnerability
- gv-dsp_lpr_v21 vulnerability
- GV-DSP_LPR_V31 vulnerability
- gv-dsp_lpr_v3_firmware1 vulnerability
- gv-ebl11001 vulnerability
- GV-Edge Recording Manager1 vulnerability
- gv-efd11001 vulnerability
- gv-fd24101 vulnerability
- gv-fd34001 vulnerability
- gv-fd34011 vulnerability
- gv-fe4201 vulnerability
- gv-lx_4_v21 vulnerability
- gv-lx_4_v31 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-11120CRITICAL | GeoVision EOL devices - OS Command InjectionCertain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports. CWE-78Nov 15, 2024 | CVSS9.8v3.1 | EPSS28.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6047CRITICAL | GeoVision EOL device - OS Command InjectionCertain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. CWE-78Jun 17, 2024 | CVSS9.8v3.1 | EPSS10.1% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |