---
cve: "CVE-2024-6047"
severity: "CRITICAL"
cvss: 9.8
epss: "10.1%"
vendor: "GeoVision"
kev: true
exploited: true
published: "2024-06-17 06:15:09"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T10:03:42+02:00"
---

# CVE-2024-6047

> 9.8 CRITICAL · ⚠️ CISA KEV (491 Tage) · 🔓 Exploited

## Beschreibung

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html>
- <https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html>
- <https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-6047>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-6047) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
