Geovision

Gv-lpc2211

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 10.09.2026 08:26:16
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources.

  • EPSS 0.33%
  • Veröffentlicht 10.09.2026 08:25:41
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR serv...

  • EPSS 0.31%
  • Veröffentlicht 10.09.2026 08:24:57
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process.

  • EPSS 0.26%
  • Veröffentlicht 10.09.2026 08:24:36
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections.

  • EPSS 0.27%
  • Veröffentlicht 10.09.2026 08:24:15
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.

  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 08:23:57
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 08:23:36
  • Zuletzt bearbeitet 10.09.2026 16:18:10

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

  • EPSS 0.3%
  • Veröffentlicht 10.09.2026 08:23:11
  • Zuletzt bearbeitet 10.09.2026 16:18:09

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.

  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 08:22:48
  • Zuletzt bearbeitet 10.09.2026 16:18:09

GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.

  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 08:22:34
  • Zuletzt bearbeitet 10.09.2026 16:18:09

GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.