Impact
This vulnerability is an authenticated stack buffer overflow that occurs during SSVR fragment reassembly. The overflow can be triggered by a legitimate user who has access to the SSVR service and causes the service to crash, resulting in a denial of service. The flaw does not provide an attacker with code execution or remote access, but it disrupts the operation of the SSVR service.
Affected Systems
Affected products are GeoVision Inc. DVR cameras GV‑LPC2011 and GV‑LPC2211 running firmware versions 1.13 and 1.14. Both firmware releases are listed as vulnerable by the CNA. No other vendors or product lines are reported to be affected.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as high severity, but the EPSS score is unavailable and the vulnerability is not listed in CISA KEV. Exploitation requires authenticated access, so an attacker must first obtain valid credentials, typically by accessing the local network. Once authenticated, the attacker can send crafted SSVR packets that trigger the stack overflow, causing the SSVR service to crash. The attack vector is therefore limited to the local network unless remote SSVR access is enabled.
OpenCVE Enrichment