CVE-2024-6047 affects GeoVision multiple devices and is described as an OS command injection vulnerability. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on 2025-05-07, which makes it a high-priority remediation item for any environment that uses the affected GeoVision products. The KEV record sets a remediation due date of 2025-05-28 and directs organizations to apply [truncated]
CVE-2024-11120 is a GeoVision OS command injection vulnerability affecting GeoVision Multiple Devices and listed by CISA in the Known Exploited Vulnerabilities catalog. Because CISA has marked it as known exploited, defenders should treat it as a high-priority exposure and act on the vendor’s mitigations or remove the product if mitigation is not available.