Description
GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
Published: 2026-09-10
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The flaw occurs when an authenticated administrator issues an ONVIF SetUser command with a password that exceeds the size of the fixed stack buffer in the GV‑LPC2211 V1.13 firmware. The overflow corrupts the stack, causing the ONVIF worker to terminate, which results in a denial of service targeting the ONVIF service. Because the vulnerability is triggered by an authenticated account, it does not provide broader system compromise; it merely disrupts service availability for the device.

Affected Systems

Affected devices are GeoVision Inc. GV‑LPC2011/LPC2211 models running firmware versions 1.13 and 1.14. The vulnerability is present in the ONVIF SetUser handling code of these firmware releases.

Risk and Exploitability

The CVSS base score of 4.9 indicates a moderate level of severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The attack requires administrative access, so the risk is limited to environments where such credentials exist. Nonetheless, the potential for internal denial of service warrants mitigation.

Generated by OpenCVE AI on September 10, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to a firmware release that resolves the ONVIF SetUser password buffer overflow.
  • Restrict ONVIF administration privileges to trusted personnel and enforce least‑privilege principles.
  • Disable or limit the ONVIF SetUser functionality if updating the firmware is not feasible.
  • Monitor device logs for repeated crashes or restarts of the ONVIF worker to detect exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.
Title GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-121
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:v1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T08:22:34.747Z

Reserved: 2026-09-10T02:56:04.082Z

Link: CVE-2026-88280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T09:17:05.007

Modified: 2026-09-10T09:17:05.007

Link: CVE-2026-88280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:30:10Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow