EXPOSURES › CVE-2024-11120
CVE-2024-11120
HIGH ⌖ ON CISA KEV · EXPLOITEDGeoVision devices have a critical, actively exploited OS command injection vulnerability allowing remote code execution without authentication, potentially impacting DIB organizations using these devices for surveillance or security purposes.
Multiple GeoVision devices are vulnerable to OS command injection, enabling unauthenticated attackers to execute arbitrary commands remotely. This poses a significant risk of data compromise and system takeover, potentially impacting NIST 800-171 compliance and requiring immediate mitigation, including discontinuing product use. DIB organizations should immediately inventory and decommission affected devices.
Shame score — The vulnerability's ease of exploitation, lack of authentication requirement, and active exploitation in the wild demonstrate a serious failure in secure coding practices and device hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.