CVE-2024-11120

Scores

EPSS

0.661medium66.1%
0%20%40%60%80%100%

Percentile: 66.1%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

78CWE-78

Related Vulnerabilities

Exploits

Exploit ID: CVE-2024-11120

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Vulnerable Software (5)

Type: Configuration

Vendor: *

Product: gv-dsp_lpr_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:geovision:gv-dsp_lpr_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator"...

Source: nvd

Type: Configuration

Vendor: *

Product: gv-vs11_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:geovision:gv-vs11_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "...

Source: nvd

Type: Configuration

Vendor: *

Product: gv-vs12_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:geovision:gv-vs12_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "...

Source: nvd

Type: Configuration

Vendor: *

Product: gvlx_4_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: gvlx_4_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

End of list