Impact
GeoVision GV-LPCLPC2011/2211 firmware versions 1.13 and 1.14 do not enforce freshness or nonce reuse for ONVIF UsernameToken messages. An attacker who captures a PasswordDigest authentication token can replay it later to perform ONVIF operations as an authenticated user. This allows the attacker to control the device, exfiltrate data, or disrupt service. The vulnerability is an example of CWE‑294, an improper authentication weakness that enables replay attacks.
Affected Systems
The affected systems are GeoVision Inc. devices running GV-LPC2211 firmware, specifically versions 1.13 and 1.14.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, but the lack of an existing CSIRT mitigation and the common exposure of ONVIF services over the network suggest a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the ability to replay authentication tokens remains a grave security risk. Based on the description, the likely attack vector is remote network access to the ONVIF interface, where an attacker can capture and reuse a valid PasswordDigest. The attack only requires network connectivity to the device, no local privileges, and sufficient bandwidth to capture traffic.
OpenCVE Enrichment