Description
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.

The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.



#### disconnect command index-out-of-bound
Published: 2026-07-02
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unvalidated index parameter in the GeoWebPlayer websocket command handler allows an attacker to cause out-of-bounds memory reads, potentially exposing arbitrary memory contents. The vulnerability is documented as a range check failure (CWE-129) and could compromise confidentiality if sensitive data resides in the affected memory regions.

Affected Systems

GeoVision Inc.’s GeoWebPlayer component, specifically version 1.1.1.0 running on either 64‑bit or Windows platforms, is susceptible. The issue is addressed in GeoWebPlayer V1.1.3.0, which implements bounds checking for the index field in websocket commands.

Risk and Exploitability

The base CVSS score of 8.3 indicates high severity; the EPSS score of less than 1% suggests low observed exploitation probability, and it is not listed in CISA KEV catalogs. Exploitation requires an attacker to send a crafted websocket request to the server. The component typically listens on localhost, making local access the most likely vector, but if the service is exposed to external networks, remote exploitation becomes feasible. Successful exploitation would allow the attacker to read arbitrary memory and gain confidential information.

Generated by OpenCVE AI on July 21, 2026 at 12:32 UTC.

Remediation

Vendor Solution

The vulnerability has been patched with GeoWebPlayer V1.1.3.0


OpenCVE Recommended Actions

  • Upgrade GeoWebPlayer to version 1.1.3.0, which adds bounds checking to the websocket handler.
  • If websocket functionality is unnecessary, uninstall or disable the GeoWebPlayer addon to eliminate the vulnerable interface.
  • Restrict access to the websocket port to the local host or block external traffic with a firewall or network segmentation to limit exposure to trusted hosts.
  • Monitor logs for anomalous websocket activities or repeated index‑error messages to detect attempted exploitation attempts.

Generated by OpenCVE AI on July 21, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound. #### disconnect command index-out-of-bound
Title GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
First Time appeared Geovision Inc.
Geovision Inc. geowebplayer
Weaknesses CWE-129
CPEs cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.1.0:*:windows:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:64_bit:*:*:*:*:*
cpe:2.3:a:geovision_inc.:geowebplayer:v1.1.3.0:*:windows:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. geowebplayer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Geovision Inc. Geowebplayer
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-07-02T12:40:45.176Z

Reserved: 2026-06-24T05:48:03.740Z

Link: CVE-2026-57269

cve-icon Vulnrichment

Updated: 2026-07-02T12:40:39.711Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index