PatchSiren cyber security CVE debrief
CVE-2023-6919 Biges Safe Life Technologies Electronics Inc. CVE debrief
CVE-2023-6919 is a path traversal vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard products, published by NVD on 2024-01-26 and last modified on 2026-05-20. The vulnerability allows absolute path traversal via '/../filedir' sequences, enabling unauthenticated remote attackers to read arbitrary files on affected systems. The CVSS 3.1 score of 7.5 (HIGH) reflects network attack vector, low attack complexity, no required privileges or user interaction, and high confidentiality impact with no integrity or availability impact. Multiple VGuard firmware products are affected, including VG-4C1A-LRU, VG-4C1A-LRPU, VG-255A-BF, VG-255-BV, VG-255-DF, VG-64C8RD-NVR, VG-4C1E-NVR, VG-8C1E-NVR, and VG-8C1A-LRPU, all with firmware versions prior to V500.0003.R008.4011.C0012.B351.C. The vulnerability was reported through Turkish national cybersecurity channels (USOM/TR-24-0054). No known exploitation in ransomware campaigns has been documented, and the vulnerability is not listed in CISA KEV.
- Vendor
- Biges Safe Life Technologies Electronics Inc.
- Product
- VGuard
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-01-26
- Original CVE updated
- 2026-05-20
- Advisory published
- 2024-01-26
- Advisory updated
- 2026-05-20
Who should care
Organizations deploying Biges VGuard surveillance and security systems, particularly those with internet-exposed management interfaces. System integrators and managed security service providers maintaining VGuard deployments for commercial, industrial, or government clients. Network security teams responsible for IoT and surveillance device segmentation.
Technical summary
The vulnerability exists in the VGuard firmware's handling of file path parameters, where insufficient sanitization of directory traversal sequences ('/../filedir') allows attackers to escape intended directory constraints and access arbitrary files on the underlying filesystem. The attack can be performed remotely without authentication, making exposed management interfaces particularly vulnerable. The CVSS vector indicates network accessibility with no privilege requirements, though exploitation is limited to confidentiality impact (file read) without ability to modify system state or cause denial of service.
Defensive priority
HIGH
Recommended defensive actions
- Apply firmware update to version V500.0003.R008.4011.C0012.B351.C or later for all affected VGuard product models
- Restrict network access to VGuard device management interfaces to trusted administrative hosts only
- Monitor for suspicious file access patterns or unauthorized configuration exports from VGuard systems
- Review access logs for indicators of path traversal exploitation attempts
- Contact Biges Safe Life Technologies Electronics Inc. for additional hardening guidance if firmware update is not immediately available
Evidence notes
Vulnerability description and affected product list derived from NVD CPE criteria and CVE description. CVSS vector confirmed as AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Advisory source TR-24-0054 from Turkish National Cyber Security Incident Response Center (USOM) provides original disclosure. No KEV entry present.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-6919 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-6919
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-6919 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-6919
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-0054
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-24-0054
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.