'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-03-25 | |
| Rule Name: | GeoVision IoT DateSetting.cgi szSrvIpAddr Command Injection Vulnerability (CVE-2024-6047) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | GeoVisionis a Taiwanese manufacturer of security surveillance equipment. Its products include IP cameras, access control controllers, and video servers. The time setting interfaces of several discontinued devices have input validation flaws, allowing unauthorized attackers to remotely execute arbitrary commands. This vulnerability can lead to complete control of the devices. | |
| Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet |
|
| Solutions |
|---|
| Refer to the announcement or patch by the vendor. |