Impact
GeoVision’s GV‑LPC2211 firmware version 1.13 contains a stack‑frame overflow flaw when handling ONVIF WS‑Discovery Probe requests. An unauthenticated client that sends an excessive number of Scopes tokens overwrites stack control data and crashes the discovery service, resulting in a denial of service. The vulnerability is a classic buffer overflow (CWE‑121) with no evidence of remote code execution.
Affected Systems
The flaw affects GeoVision Inc.’s GV‑LPC2011/LPC2211 device firmware v1.13; the common platform enumeration also lists v1.14, but only v1.13 is documented as vulnerable. Users should verify the exact firmware build on each device.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The attack vector is remote and requires no authentication; a malicious actor can send a crafted Probe from any network that can reach the device. The exploit involves sending an oversized Scopes list, triggering a stack overflow that crashes the discovery process and disrupts service availability. The EPSS score is not available, so the current likelihood of exploitation is unknown but non‑negligible for exposed devices.
OpenCVE Enrichment