CVE-2024-11120: GeoVision Devices OS Command Injection Vulnerability
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.
Other sources
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GeoVision Multiple Devicesfrom your environment.Discontinue product utilization of affected GeoVision Multiple Devices (EoL/EoS). Remove affected devices from the environment and replace them with supported alternatives.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services (as referenced in the advisory) to implement compensating controls for affected systems hosted in cloud environments.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11120?
CVE-2024-11120 is classified as a high severity vulnerability due to its potential for unauthenticated remote command execution.
How do I fix CVE-2024-11120?
To fix CVE-2024-11120, update affected GeoVision devices to the latest firmware version provided by the manufacturer.
What types of devices are affected by CVE-2024-11120?
CVE-2024-11120 affects certain EOL (end-of-life) GeoVision devices, including models GV-VS11, GV-VS12, and GV-DSP LPR.
Can CVE-2024-11120 be exploited remotely?
Yes, CVE-2024-11120 can be exploited remotely by unauthenticated attackers to execute arbitrary system commands.
Has CVE-2024-11120 been actively exploited in the wild?
Yes, CVE-2024-11120 has been reported to have already been exploited by attackers to install malware.