Executive brief
GeoVision GV-LPC2211 is an IP-based camera system that manages video streams and network security. A stack buffer overflow vulnerability in the SSVR (Surveillance Server) service allows an authenticated user to crash the service, causing a denial of service and disruption to surveillance operations.
Technical details
The vulnerability is an authenticated stack buffer overflow in the SSVR fragment reassembly mechanism of GeoVision GV-LPC2211 V1.13. An attacker with valid user credentials can exploit this by sending a specially crafted message during SSVR fragment reassembly, causing the service to crash. The attack requires authentication and network access to the device. Exploitation results in a denial of service condition affecting the surveillance server. GeoVision has been informed and is expected to provide patches through their normal security update process.
Affected products
- GeoVision GV-LPC2211 V1.13
Timeline
- 2026-09-10: disclosed