Impact
GeoWebPlayer, also known as the Web Plugin or WS Player, expands the functionality of GeoVision’s video management and cloud platforms by running a WebSocket server that accepts commands from localhost. The server includes several commands that accept an `index` parameter, which the implementation uses directly to index internal arrays without validating that the value is within bounds. This omission allows an attacker to perform out-of-bounds reads on multiple arrays, potentially leaking sensitive data or causing unintended behavior such as crashes or denial of service.
Affected Systems
GeoVision Inc. ships GeoWebPlayer v1.1.1.0 for both 64‑bit and Windows environments as a plugin for its GV‑VMS, GV‑Cloud, and related products. The identified vulnerability exists in these builds; official remediation is provided in GeoWebPlayer v1.1.3.0, as indicated by the vendor’s patch release and the associated CPE entries.
Risk and Exploitability
The CVSS vulnerability as high severity. The EPSS score of less than 1 % indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog, suggesting no known public exploits. Based on the description, it is inferred that the from localhost, implying a local attack vector that would require an attacker to obtain local code execution or use a lateral attack to reach the target system. No exploitation prerequisites beyond local access are mentioned in the provided data.
OpenCVE Enrichment