Impact
A buffer overflow exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The software does not validate the length of the Protocol parameter within the Transport element. By sending a SOAP request containing an oversized protocol string, an attacker can overflow the stack buffer and overwrite the return instruction pointer, potentially causing the device to crash or enabling the execution of arbitrary code.
Affected Systems
The vulnerability affects LSC Indoor Camera running version 7.6.32. No other vendor or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and the vulnerability is exploitable over the network through the ONVIF service. The attack does not require authentication and can be carried out by an external adversary who can send malformed SOAP requests. Although the EPSS score is not available and the vulnerability is not yet in the CISA KEV catalog, the potential for remote code execution makes it a significant risk for any network exposed to ONVIF traffic.
OpenCVE Enrichment