Description
GeoVision GV-LPC2211
V1.13 contains an authenticated stack buffer overflow in SSVR fragment
reassembly that allows a valid user to crash the SSVR service.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

This vulnerability is an authenticated stack buffer overflow that occurs during SSVR fragment reassembly. The overflow can be triggered by a legitimate user who has access to the SSVR service and causes the service to crash, resulting in a denial of service. The flaw does not provide an attacker with code execution or remote access, but it disrupts the operation of the SSVR service.

Affected Systems

Affected products are GeoVision Inc. DVR cameras GV‑LPC2011 and GV‑LPC2211 running firmware versions 1.13 and 1.14. Both firmware releases are listed as vulnerable by the CNA. No other vendors or product lines are reported to be affected.

Risk and Exploitability

The CVSS score of 6.5 classifies the issue as high severity, but the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated access, so an attacker must first obtain valid credentials, typically by accessing the local network. Once authenticated, the attacker can send crafted SSVR packets that trigger the stack overflow, causing the SSVR service to crash. The attack vector is therefore limited to the local network unless remote SSVR access is enabled.

Generated by OpenCVE AI on September 10, 2026 at 10:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether GeoVision has released a firmware update that removes the stack overflow; apply the update when it becomes available.
  • Restrict access to the SSVR service to trusted internal hosts or disable the service entirely if it is not required for operations.
  • Implement network segmentation so that traffic involving the SSVR service is isolated from critical systems and monitoring tools.

Generated by OpenCVE AI on September 10, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.
Title GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
Weaknesses CWE-121
CPEs cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpclpc2011 2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T12:49:39.019Z

Reserved: 2026-09-10T02:56:02.024Z

Link: CVE-2026-88268

cve-icon Vulnrichment

Updated: 2026-09-10T12:49:34.156Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:03.650

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-88268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow