Description
GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
Published: 2026-09-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

GeoVision’s GV‑LPC2211 firmware version 1.13 contains a stack‑frame overflow flaw when handling ONVIF WS‑Discovery Probe requests. An unauthenticated client that sends an excessive number of Scopes tokens overwrites stack control data and crashes the discovery service, resulting in a denial of service. The vulnerability is a classic buffer overflow (CWE‑121) with no evidence of remote code execution.

Affected Systems

The flaw affects GeoVision Inc.’s GV‑LPC2011/LPC2211 device firmware v1.13; the common platform enumeration also lists v1.14, but only v1.13 is documented as vulnerable. Users should verify the exact firmware build on each device.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The attack vector is remote and requires no authentication; a malicious actor can send a crafted Probe from any network that can reach the device. The exploit involves sending an oversized Scopes list, triggering a stack overflow that crashes the discovery process and disrupts service availability. The EPSS score is not available, so the current likelihood of exploitation is unknown but non‑negligible for exposed devices.

Generated by OpenCVE AI on September 10, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware update from GeoVision that corrects the Scopes token bound check, if available.
  • If an update is not yet released, disable the ONVIF WS‑Discovery service or confine it to a trusted internal subnet.
  • Configure network firewalls to block unsolicited ONVIF Probe traffic from untrusted sources.

Generated by OpenCVE AI on September 10, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.
Title GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
First Time appeared Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
Weaknesses CWE-121
CPEs cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.13:*:*:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-lpc2011_lpc2211:1.14:*:*:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-lpc2011 Lpc2211
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Geovision Inc. Gv-lpc2011 Lpc2211
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-09-10T15:06:51.366Z

Reserved: 2026-09-10T02:56:04.083Z

Link: CVE-2026-88287

cve-icon Vulnrichment

Updated: 2026-09-10T15:06:43.871Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:05.787

Modified: 2026-09-10T16:18:10.457

Link: CVE-2026-88287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:45:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow