Back to Database
Status published
Critical
CVE-2024-6047
GeoVision EOL device - OS Command Injection
Vulnerability Description
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-6047
Credits & Attribution
No credits recorded in the NVD database.
References
More from GeoVision
View All →CVE-2024-12553
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability
Medium
6.5
CVE-2024-11120
GeoVision EOL devices - OS Command Injection
Critical
9.8
CVE-2020-3931
GeoVision Door Access Control Device - Buffer overflow vulnerability
Critical
9.8
CVE-2020-3930
GeoVision Door Access Control Device - Information disclosure vulnerability
Medium
4
CVE-2020-3929
GeoVision Door Access Control Device - Shared cryptographic keys
Medium
5.9
Affected Vendor
GeoVision
View all reports →Affected Software
GV_DSP_LPR_V2, GV_IPCAMD_GV_BX1500, GV_IPCAMD_GV_CB220, GV_IPCAMD_GV_EBL1100, GV_IPCAMD_GV_EFD1100, GV_IPCAMD_GV_FD2410, GV_IPCAMD_GV_FD3400, GV_IPCAMD_GV_FE3401, GV_IPCAMD_GV_FE420, GV-VS14_VS14, GV_VS03, GV_VS2410, GV_VS28XX, GV_VS216XX, GV VS04A, GV VS04H, GVLX 4 V2, GVLX 4 V3, GV_IPCAMD_GV_BX130, GV_GM8186_VS14
Vulnerable Versions:
all
Timeline
Official Publish:
June 17th, 2024
Last Modified:
October 21st, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H