PatchSiren cyber security CVE debrief
CVE-2023-6919 Biges Safe Life Technologies Electronics Inc. CVE debrief
CVE-2023-6919 is a path traversal vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard products, published by NVD on 2024-01-26 and last modified on 2026-05-20. The vulnerability allows absolute path traversal via '/../filedir' sequences, enabling unauthenticated remote attackers to read arbitrary files on affected systems. The CVSS 3.1 score of 7.5 (HIGH) reflects network attack vector, low attack complexity, no required privileges or user interaction, and high confidentiality impact with no integrity or availability impact. Multiple VGuard firmware products are affected, including VG-4C1A-LRU, VG-4C1A-LRPU, VG-255A-BF, VG-255-BV, VG-255-DF, VG-64C8RD-NVR, VG-4C1E-NVR, VG-8C1E-NVR, and VG-8C1A-LRPU, all with firmware versions prior to V500.0003.R008.4011.C0012.B351.C. The vulnerability was reported through Turkish national cybersecurity channels (USOM/TR-24-0054). No known exploitation in ransomware campaigns has been documented, and the vulnerability is not listed in CISA KEV.
- Vendor
- Biges Safe Life Technologies Electronics Inc.
- Product
- VGuard
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-01-26
- Original CVE updated
- 2026-05-20
- Advisory published
- 2024-01-26
- Advisory updated
- 2026-05-20
Who should care
Organizations deploying Biges VGuard surveillance and security systems, particularly those with internet-exposed management interfaces. System integrators and managed security service providers maintaining VGuard deployments for commercial, industrial, or government clients. Network security teams responsible for IoT and surveillance device segmentation.
Technical summary
The vulnerability exists in the VGuard firmware's handling of file path parameters, where insufficient sanitization of directory traversal sequences ('/../filedir') allows attackers to escape intended directory constraints and access arbitrary files on the underlying filesystem. The attack can be performed remotely without authentication, making exposed management interfaces particularly vulnerable. The CVSS vector indicates network accessibility with no privilege requirements, though exploitation is limited to confidentiality impact (file read) without ability to modify system state or cause denial of service.
Defensive priority
HIGH
Recommended defensive actions
- Apply firmware update to version V500.0003.R008.4011.C0012.B351.C or later for all affected VGuard product models
- Restrict network access to VGuard device management interfaces to trusted administrative hosts only
- Monitor for suspicious file access patterns or unauthorized configuration exports from VGuard systems
- Review access logs for indicators of path traversal exploitation attempts
- Contact Biges Safe Life Technologies Electronics Inc. for additional hardening guidance if firmware update is not immediately available
Evidence notes
Vulnerability description and affected product list derived from NVD CPE criteria and CVE description. CVSS vector confirmed as AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Advisory source TR-24-0054 from Turkish National Cyber Security Incident Response Center (USOM) provides original disclosure. No KEV entry present.
Official resources
-
CVE-2023-6919 CVE record
CVE.org
-
CVE-2023-6919 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
2024-01-26