peter bassill · operator
$ cve CVE-2024-11120 JSON

CVE-2024-11120 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 28.4% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2025-05-28.

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS28.39% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-05-28
Public exploitnone known
Published2024-11-15
Last modified2026-06-17

CISA KEV

NameGeoVision Devices OS Command Injection Vulnerability
Added2025-05-07
Due2025-05-28
Vendor / productGeoVision / Multiple Devices
Ransomware usenone reported

Affected (8)

VendorProduct
geovisiongv-dsp lpr
geovisiongv-dsp lpr firmware
geovisiongv-vs11
geovisiongv-vs11 firmware
geovisiongv-vs12
geovisiongv-vs12 firmware
geovisiongvlx 4
geovisiongvlx 4 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD