{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-6047",
  "revision": 1,
  "title": "GeoVision devices — unfiltered input (CVE-2024-6047)",
  "summary": "Discontinued GeoVision devices fail to filter user input on one function, so an unauthenticated attacker runs system commands on them. It is one of two such flaws the same botnet campaign uses.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.10072,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2025-05-07",
    "prerequisites": "Network access to the device's web interface; no credentials needed."
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Replace these devices — they are past end of life; a second command injection in the same products is listed alongside this one.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-6047",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-6047",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-6047",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6047",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet"
    },
    {
      "type": "writeup",
      "url": "https://www.twcert.org.tw/en/cp-139-7884-c5a8b-2.html"
    },
    {
      "type": "writeup",
      "url": "https://www.twcert.org.tw/tw/cp-132-7883-f5635-1.html"
    }
  ],
  "published_at": "2024-06-17T06:15:09.237Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "geovision",
    "iot",
    "command-injection",
    "mirai",
    "end-of-life",
    "kev"
  ]
}
