Description
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability.
Problem types
CWE-121 Stack-based buffer overflow
Product status
V20.0.2
V20.1.0.0
Timeline
| 2026-04-21: | Initial Vendor Contact |
Credits
Philippe Laulheret of Cisco Talos.
Kelly Patterson of Cisco Talos.
Robert Sherwin of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2026-2411
www.geovision.com.tw/cyber_security.php
talosintelligence.com/vulnerability_reports/TALOS-2026-2411