CVE-2024-11120 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 28.4% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2025-05-28.
Description
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 28.39% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2025-05-28 |
| Public exploit | none known |
| Published | 2024-11-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | GeoVision Devices OS Command Injection Vulnerability |
|---|---|
| Added | 2025-05-07 |
| Due | 2025-05-28 |
| Vendor / product | GeoVision / Multiple Devices |
| Ransomware use | none reported |
Affected (8)
| Vendor | Product |
|---|---|
| geovision | gv-dsp lpr |
| geovision | gv-dsp lpr firmware |
| geovision | gv-vs11 |
| geovision | gv-vs11 firmware |
| geovision | gv-vs12 |
| geovision | gv-vs12 firmware |
| geovision | gvlx 4 |
| geovision | gvlx 4 firmware |
References
→ the Explorer · watch your stack · NVD