Impact
The flaw occurs when an authenticated administrator issues an ONVIF SetUser command with a password that exceeds the size of the fixed stack buffer in the GV‑LPC2211 V1.13 firmware. The overflow corrupts the stack, causing the ONVIF worker to terminate, which results in a denial of service targeting the ONVIF service. Because the vulnerability is triggered by an authenticated account, it does not provide broader system compromise; it merely disrupts service availability for the device.
Affected Systems
Affected devices are GeoVision Inc. GV‑LPC2011/LPC2211 models running firmware versions 1.13 and 1.14. The vulnerability is present in the ONVIF SetUser handling code of these firmware releases.
Risk and Exploitability
The CVSS base score of 4.9 indicates a moderate level of severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The attack requires administrative access, so the risk is limited to environments where such credentials exist. Nonetheless, the potential for internal denial of service warrants mitigation.
OpenCVE Enrichment