Impact
GeoVision's GV‑LPC2211 firmware version 1.13 fails to properly manage PTZ connection state. An unauthenticated remote client can send requests that block the PTZ accept loop, which stops the device from accepting any new PTZ connections until the system is restarted. This denial‑of‑service condition effectively disables remote camera control and can disrupt monitoring operations.
Affected Systems
The vulnerability affects devices running GeoVision GV‑LPC2211 firmware version 1.13. The product range GV‑LPC2011/LPC2211 is listed as vulnerable for this version; firmware 1.14 is available and is presumed to contain the fix.
Risk and Exploitability
The CVSS score of 7.5 reflects a high‑impact denial‑of‑service vulnerability. The EPSS score is not available and the issue is not yet listed in CISA KEV, indicating no publicly confirmed exploits at this time. Attackers only need network access to the PTZ service and do not require authentication to trigger the loop, leading to immediate disruption of PTZ functionality.
OpenCVE Enrichment