Impact
The vulnerability is a stack buffer overflow caused by the ONVIF DeleteUsers operation failing to limit repeated Username elements. When an authenticated administrator submits a request with many Username entries, the service overflows an array and crashes. This results in a denial‑of‑service for the ONVIF interface, potentially blocking camera control or monitoring. The weakness follows CWE‑121, a stack‑based buffer overflow.
Affected Systems
The flaw has been identified in GeoVision Inc.'s GV‑LPC2011/LPC2211 firmware version 1.13. The CPE data includes firmware 1.14 as well, but the advisory does not confirm whether 1.14 contains the fix or remains vulnerable. Therefore, devices running 1.13, and by default 1.14 unless otherwise noted, should be considered potentially affected.
Risk and Exploitability
The CVSS score of 4.9 points to moderate severity. Exploitation requires authenticated administrative access, indicating an internally‑derived attacker or compromised admin credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Nevertheless, any administrator who can issue privileged DeleteUsers requests could repeatedly crash the service, disrupting camera availability.
OpenCVE Enrichment