Impact
GeoVision GV‑LPC2211 versions 1.13 and 1.14 expose a flaw that permits a Guest user to enter SSVR firmware‑upgrade mode without proper validation, causing live services to be torn down. The result is a disruption of availability, fitting the category of a Denial of Service vulnerability. The weakness is a missing access control (CWE‑862), which allows unauthenticated or low‑privileged users to trigger a service‑teardown sequence before the firmware image is verified.
Affected Systems
The affected devices are GEO Vision’s GV‑LPC2011/LPC2211 embedded controllers, specifically firmware releases 1.13 and 1.14 as listed by the vendor. These models run the SSVR firmware upgrade service and are deployed in security‑camera and surveillance hardware.
Risk and Exploitability
This vulnerability carries a CVSS score of 6.5, indicating moderate severity. No EPSS data is available, so current exploit likelihood is unknown, and the issue is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is through device interfaces that allow a Guest user to submit upgrade commands, such as a web or local management console. The risk is that any attacker with access to a Guest account could disrupt device operation, impacting service availability.
OpenCVE Enrichment