A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
The vulnerability results from a stack overflow error (CWE-787) in the WebCam Server login handler module. The attacker sends a specially crafted HTTP request to the vulnerable endpoint, which causes a buffer overflow on the stack. This results in overwriting data that controls program execution, allowing the attacker to execute arbitrary code in the context of the server process. Exploitation requires no prior authentication or user interaction.
An attacker can gain the ability to execute arbitrary code on the device (RCE), which can lead to complete takeover of the video management system, loss of recording confidentiality, violation of system integrity, and its unavailability.
Apply patches available from the manufacturer according to the references. The manufacturer provides information about security updates at https://www.geovision.com.tw/cyber_security.php. Until patches are applied, it is recommended to restrict network access to the WebCam Server interface only to trusted IP addresses and to isolate GV-VMS devices in a separate network segment (VLAN) behind a firewall.
GeoVision GV-VMS V20, version 20.0.2 (GeoVision GV-VMS Firmware and GeoVision GV-VMS application)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HGeovision Gv Vms
HWGeovision20Geovision Gv Vms Firmware
OSGeovision< 21.0.0
Related vulnerabilities
Stack overflow w GeoVision GV-VMS — niezautoryzowane RCE przez WebCam Server
OS Command Injection w urządzeniach GeoVision — zdalne wykonanie poleceń bez uwierzytelnienia
Command injection w urządzeniach GeoVision EOL — zdalne wykonanie poleceń
Command injection w GeoVision LPC2011/LPC2211 via konfiguracja DDNS
Privilege escalation w interfejsie Web GeoVision LPC2011/LPC2211