Impact
GeoVision GV-LPC2211 V1.13 allows an authenticated administrator to send multiple User elements in an ONVIF CreateUsers request without proper limits, which can overwrite stack control state and crash the ONVIF worker. The resulting stack-frame overflow leads to a denial of service for the affected device. The weakness corresponds to CWE-121, a stack-based buffer overwrite.
Affected Systems
GeoVision Inc. GV-LPC2011/LPC2211, version 1.13. The product is also identified in the Common Platform Enumeration list for versions 1.13 and 1.14, but only version 1.13 is explicitly affected by the described vulnerability.
Risk and Exploitability
The CVSS base score of 4.9 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog. The vulnerability requires authenticated administrator privileges, so attack requires legitimate or compromised credentials. If an attacker gains such access, the stack overflow can be triggered, leading to an application crash and loss of availability.
OpenCVE Enrichment