boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-11120

GeoVision EOL devices - OS Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .2839   98.1   YES
AFFECTED
  Product        Versions     Fixed
  GV-VS12        unspecified  —
  GV-VS11        unspecified  —
  GV-DSP_LPR_V3  unspecified  —
  GVLX 4 V2      unspecified  —
  GVLX 4 V3      unspecified  —
TIMELINE
  Nov 12  Reserved by twcert
  Nov 15  Published (CNA: twcert)
  May 7   Added to CISA KEV, remediation due 2025-05-28
CWE-78 · CNA: twcert · CVSS v3.1 · 4 references · KEV due May 28, 2025

Description

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
November 12, 2024ReservedReserved by twcert
November 15, 2024PublishedPublished (CNA: twcert)
May 7, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-05-28

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
GeoVisionGV-VS12———
GeoVisionGV-VS11———
GeoVisionGV-DSP_LPR_V3———
GeoVisionGVLX 4 V2———
GeoVisionGVLX 4 V3———

Weaknesses

CWE-78

References (4)

Related

Authoritative record: CVE-2024-11120 at cve.org

Vendors: geovision

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-11120 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.