PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-6919 Biges Safe Life Technologies Electronics Inc. CVE debrief

CVE-2023-6919 is a path traversal vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard products, published by NVD on 2024-01-26 and last modified on 2026-05-20. The vulnerability allows absolute path traversal via '/../filedir' sequences, enabling unauthenticated remote attackers to read arbitrary files on affected systems. The CVSS 3.1 score of 7.5 (HIGH) reflects network attack vector, low attack complexity, no required privileges or user interaction, and high confidentiality impact with no integrity or availability impact. Multiple VGuard firmware products are affected, including VG-4C1A-LRU, VG-4C1A-LRPU, VG-255A-BF, VG-255-BV, VG-255-DF, VG-64C8RD-NVR, VG-4C1E-NVR, VG-8C1E-NVR, and VG-8C1A-LRPU, all with firmware versions prior to V500.0003.R008.4011.C0012.B351.C. The vulnerability was reported through Turkish national cybersecurity channels (USOM/TR-24-0054). No known exploitation in ransomware campaigns has been documented, and the vulnerability is not listed in CISA KEV.

Vendor
Biges Safe Life Technologies Electronics Inc.
Product
VGuard
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-01-26
Original CVE updated
2026-05-20
Advisory published
2024-01-26
Advisory updated
2026-05-20

Who should care

Organizations deploying Biges VGuard surveillance and security systems, particularly those with internet-exposed management interfaces. System integrators and managed security service providers maintaining VGuard deployments for commercial, industrial, or government clients. Network security teams responsible for IoT and surveillance device segmentation.

Technical summary

The vulnerability exists in the VGuard firmware's handling of file path parameters, where insufficient sanitization of directory traversal sequences ('/../filedir') allows attackers to escape intended directory constraints and access arbitrary files on the underlying filesystem. The attack can be performed remotely without authentication, making exposed management interfaces particularly vulnerable. The CVSS vector indicates network accessibility with no privilege requirements, though exploitation is limited to confidentiality impact (file read) without ability to modify system state or cause denial of service.

Defensive priority

HIGH

Recommended defensive actions

  • Apply firmware update to version V500.0003.R008.4011.C0012.B351.C or later for all affected VGuard product models
  • Restrict network access to VGuard device management interfaces to trusted administrative hosts only
  • Monitor for suspicious file access patterns or unauthorized configuration exports from VGuard systems
  • Review access logs for indicators of path traversal exploitation attempts
  • Contact Biges Safe Life Technologies Electronics Inc. for additional hardening guidance if firmware update is not immediately available

Evidence notes

Vulnerability description and affected product list derived from NVD CPE criteria and CVE description. CVSS vector confirmed as AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Advisory source TR-24-0054 from Turkish National Cyber Security Incident Response Center (USOM) provides original disclosure. No KEV entry present.

Official resources

2024-01-26