Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

INFO

Published Date :

2024-11-15T02:00:27.361Z

Last Modified :

2025-10-21T22:55:36.559Z

Source :

twcert
AFFECTED PRODUCTS

The following products are affected by CVE-2024-11120 vulnerability.

Vendors Products
Geovision
  • Gv-dsp Lpr
  • Gv-dsp Lpr Firmware
  • Gv-dsp Lpr V3 Firmware
  • Gv-vs11
  • Gv-vs11 Firmware
  • Gv-vs12
  • Gv-vs12 Firmware
  • Gvlx 4
  • Gvlx 4 Firmware
  • Gvlx 4 V2 Firmware
  • Gvlx 4 V3 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact