{
  "id": "CVE-2024-6047",
  "url": "https://spydr.io/cve/CVE-2024-6047",
  "published": "2024-06-17T06:15:09.237Z",
  "modified": "2026-06-17T08:17:10.453Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "cert.org.tw",
  "epss": 0.10072,
  "epss_percentile": 0.95513,
  "exploited": true,
  "kev": {
    "added": "2025-05-07",
    "due": "2025-05-28",
    "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "ransomware": "Unknown",
    "name": "GeoVision Devices OS Command Injection Vulnerability",
    "notes": "https://dlcdn.geovision.com.tw/TechNotice/CyberSecurity/Security_Advisory_IP_Device_2024-11.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2024-6047"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "GeoVision"
  ],
  "products": [
    "GeoVision GV_DSP_LPR_V2",
    "GeoVision GV_IPCAMD_GV_BX1500",
    "GeoVision GV_IPCAMD_GV_CB220",
    "GeoVision GV_IPCAMD_GV_EBL1100",
    "GeoVision GV_IPCAMD_GV_EFD1100",
    "GeoVision GV_IPCAMD_GV_FD2410",
    "GeoVision GV_IPCAMD_GV_FD3400",
    "GeoVision GV_IPCAMD_GV_FE3401",
    "GeoVision GV_IPCAMD_GV_FE420",
    "GeoVision GV-VS14_VS14",
    "GeoVision GV_VS03",
    "GeoVision GV_VS2410",
    "GeoVision GV_VS28XX",
    "GeoVision GV_VS216XX",
    "GeoVision GV VS04A",
    "GeoVision GV VS04H",
    "GeoVision GVLX 4 V2",
    "GeoVision GVLX 4 V3",
    "GeoVision GV_IPCAMD_GV_BX130",
    "GeoVision GV_GM8186_VS14"
  ],
  "cwes": [
    "CWE-78"
  ],
  "description": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6047",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
