Description
GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

GeoVision's GV‑LPC2211 firmware version 1.13 fails to properly manage PTZ connection state. An unauthenticated remote client can send requests that block the PTZ accept loop, which stops the device from accepting any new PTZ connections until the system is restarted. This denial‑of‑service condition effectively disables remote camera control and can disrupt monitoring operations.

Affected Systems

The vulnerability affects devices running GeoVision GV‑LPC2211 firmware version 1.13. The product range GV‑LPC2011/LPC2211 is listed as vulnerable for this version; firmware 1.14 is available and is presumed to contain the fix.

Risk and Exploitability

The CVSS score of 7.5 reflects a high‑impact denial‑of‑service vulnerability. The EPSS score is not available and the issue is not yet listed in CISA KEV, indicating no publicly confirmed exploits at this time. Attackers only need network access to the PTZ service and do not require authentication to trigger the loop, leading to immediate disruption of PTZ functionality.

Generated by OpenCVE AI on September 10, 2026 at 09:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GV‑LPC2211 device to firmware 1.14 or later, which contains the fix for the PTZ connection‑state loop issue.
  • If an immediate firmware upgrade is not possible, block external traffic to the PTZ control port or restrict it to trusted IP addresses using network segmentation or firewall rules.
  • After applying changes, monitor device logs and PTZ usage for repeated ignore‑connection attempts and confirm the service accepts new connections normally.

Generated by OpenCVE AI on September 10, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.
Title GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-400
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:07:23.392Z

Reserved: 2026-09-10T02:56:04.083Z

Link: CVE-2026-88286

cve-icon Vulnrichment

Updated: 2026-09-10T15:07:18.519Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:05.673

Modified: 2026-09-10T16:18:10.357

Link: CVE-2026-88286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption