PT-2026-51659 · Geovision · Gv-I/O Box 4E
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoVision GV-I/O Box 4E (affected versions not specified)
Description
The DVRSearch service, which runs by default and listens for UDP messages on port 10001, contains a stack-based buffer overflow. The issue occurs when the server reads up to 1460 bytes into a local buffer and subsequently performs an unsafe copy of the configured DNS address into a reply buffer using
memcpy() with a length derived from strlen(). An unauthenticated network attacker can send crafted UDP traffic to trigger this overflow, potentially leading to remote code execution and full compromise of confidentiality, integrity, and availability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gv-I/O Box 4E