Impact
The vulnerability in GeoVision GV-LPC2211 V1.14 allows an attacker to send crafted VLSVR requests containing attacker-controlled variable‑length fields. Because those fields are not validated before being copied into fixed‑size stack buffers, a stack buffer overflow occurs leading to a crash of the VLSVR service. The exploit does not provide code execution but results in a denial of service that can disrupt remote services and legitimate users.
Affected Systems
GeoVision Inc.'s GV-LPC2011/LPC2211 devices running firmware version 1.14 (release identifiers 260903 and 260909) are affected. The flaw exists prior to authentication, meaning any network user can trigger the crash without logging in.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating a medium‑to‑high severity, and is not listed in the CISA KEV catalog. The EPSS score is not available, so the empirical likelihood of exploitation cannot be quantified at this time. The attack vector is inferred to be remote, network‑based, where an unauthenticated attacker can send malicious VLSVR packets to provoke the buffer overflow and cause a service crash.
OpenCVE Enrichment