Impact
GeoWebPlayer provides a websocket server that accepts commands from local processes. Several commands use an 'index' parameter to access internal arrays without bounds checking, allowing an attacker to craft a command that causes an out‑of‑bounds read. The read can expose memory contents that may include configuration data or other sensitive information, or it could destabilize the application and lead to a crash. The vulnerability is thus a high‑severeness information‑disclosure flaw.
Affected Systems
The product is GeoVision Inc.'s GeoWebPlayer, version 1.1.1.0, used with GeoVision software such as GV‑VMS, GV‑Cloud and other products. The affected binary runs on Windows and 64‑bit systems. GeoVision released a fix in GeoWebPlayer 1.1.3.0 that implements bounds checking for the index parameter and removes the flaw.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity issue. The EPSS score of less than 1 % and the absence of a KEV listing suggest that exploitation is unlikely at present, and the websocket server only accepts connections from localhost, limiting the attack surface. Nonetheless, if an attacker gains local access, the out‑of‑bounds read could leak confidential memory or cause a denial of service.
OpenCVE Enrichment