Description
GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
Published: 2026-09-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access via replayed WS-Security PasswordDigest
Action: Immediate Patch
AI Analysis

Impact

GeoVision GV-LPCLPC2011/2211 firmware versions 1.13 and 1.14 do not enforce freshness or nonce reuse for ONVIF UsernameToken messages. An attacker who captures a PasswordDigest authentication token can replay it later to perform ONVIF operations as an authenticated user. This allows the attacker to control the device, exfiltrate data, or disrupt service. The vulnerability is an example of CWE‑294, an improper authentication weakness that enables replay attacks.

Affected Systems

The affected systems are GeoVision Inc. devices running GV-LPC2211 firmware, specifically versions 1.13 and 1.14.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, but the lack of an existing CSIRT mitigation and the common exposure of ONVIF services over the network suggest a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the ability to replay authentication tokens remains a grave security risk. Based on the description, the likely attack vector is remote network access to the ONVIF interface, where an attacker can capture and reuse a valid PasswordDigest. The attack only requires network connectivity to the device, no local privileges, and sufficient bandwidth to capture traffic.

Generated by OpenCVE AI on September 10, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check GeoVision’s website and support channels for a firmware update that addresses the WS‑Security PasswordDigest replay issue and install it immediately.
  • If an update is not yet available, restrict ONVIF exposure by firewalling the ONVIF port or configuring the device to accept ONVIF connections only from trusted IP addresses.
  • Consider disabling the ONVIF service entirely if the device does not require it, or replace the device with one that implements nonce or timestamp freshness checks for WS‑Security UsernameTokens.

Generated by OpenCVE AI on September 10, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.
Title GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay
First Time appeared Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
Weaknesses CWE-294
CPEs cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpclpc2011_2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpclpc2011 2211
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Gv-lpclpc2011 2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:30:12.089Z

Reserved: 2026-09-10T02:56:04.082Z

Link: CVE-2026-88278

cve-icon Vulnrichment

Updated: 2026-09-10T15:30:08.140Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:04.787

Modified: 2026-09-10T16:18:09.483

Link: CVE-2026-88278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay