Impact
GeoWebPlayer is a plugin for GeoVision video management software that runs a WebSocket server. From localhost, commands include an `index` value that is directly used to index internal arrays without validating bounds. This omission allows an attacker with local or lateral access to read memory out of bounds, potentially exposing sensitive information. The weakness is classed as CWE-129.
Affected Systems
The vulnerability affects GeoVision Inc.’s GeoWebPlayer v1.1.1.0 for both 64‑bit and Windows platforms. The vendor has released an update, GeoWebPlayer v1.1.3.0, which includes a fix for the out‑of‑bounds read. The CPE entries confirm that the patch covers the same platforms.
Risk and Exploitability
The CVSS score of 8.3 rates this a high‑severity issue. The EPSS score of less than 1 % suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog, indicating no documented public exploits. The attack vector inferred from the description is local, as the WebSocket server accepts commands only from the host. An attacker would need local code execution or a successful lateral movement to reach the target, and no additional exploitation prerequisites are mentioned.
OpenCVE Enrichment