Description
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.

The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.


#### audio command index-out-of-bound
Published: 2026-07-02
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GeoWebPlayer hosts a WebSocket server that accepts localhost commands, many of which include an `index` parameter that is used to access internal arrays. Because the value is not validated against bounds, an attacker can trigger an out‑of‑bounds read, exposing arbitrary contents from the process memory. The flaw is a classic example of CWE‑129 and does not provide an escape to remote code execution or privilege escalation, but it can leak sensitive data and compromise confidentiality.

Affected Systems

Geovision Inc.’s GeoWebPlayer addon, version 1.1.1.0 on both 64‑bit and Windows platforms, is affected. The vendor has released GeoWebPlayer V1.1.3.0, which implements bounds checking for the vulnerable commands.

Risk and Exploitability

The CVSS score of 8.3 denotes high severity, while the EPSS score of < 1% indicates an extremely low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is local access to the device via the loopback interface; an attacker can read arbitrary memory but cannot directly achieve code execution or privilege escalation.

Generated by OpenCVE AI on July 22, 2026 at 13:58 UTC.

Remediation

Vendor Solution

The vulnerability has been patched with GeoWebPlayer V1.1.3.0


OpenCVE Recommended Actions

  • Update GeoWebPlayer to version V1.1.3.0 or later to apply the bounds‑checking fix.
  • Restrict the WebSocket port by using host‑based firewall rules or access‑control lists so that only authorized local processes can communicate with the server.
  • Monitor system logs and WebSocket traffic for abnormal requests that include out‑of‑bounds index values and investigate any suspicious activity.

Generated by OpenCVE AI on July 22, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound. #### audio command index-out-of-bound
Title GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
First Time appeared Geovision Inc.
Geovision Inc. geowebplayer
Weaknesses CWE-129
CPEs cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:windows:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:windows:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. geowebplayer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Geowebplayer
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-07-02T12:29:34.294Z

Reserved: 2026-06-24T05:48:03.740Z

Link: CVE-2026-57265

cve-icon Vulnrichment

Updated: 2026-07-02T12:29:30.247Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index