Impact
GeoWebPlayer, or Web Plugin, is an addon that creates a WebSocket server for various GeoVision software. The server accepts commands from localhost, many of which include an "index" value that is used to access internal arrays without performing bounds checking. As a result, an attacker who can send a crafted WebSocket message can trigger an out‑of‑bounds read (CWE‑129). The vulnerability allows the confidential data that resides in the affected memory to be read, potentially exposing configuration values, state information or other sensitive content. It does not provide code execution or privilege escalation.
Affected Systems
The flaw affects GeoVision Inc.’s GeoWebPlayer add‑on, which is included with GV‑VMS and GV‑Cloud software suites. Versions 1.1.1.0 on both 64‑bit and Windows platforms are vulnerable; these are patched in version 1.1.3.0 and later. Other, earlier, or later versions are not listed as affected. All systems running the affected versions should assess their exposure.
Risk and Exploitability
The CVSS base score of 8.3 indicates high severity. The EPSS score of <1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires local access or an initial compromise that permits the attacker to send crafted WebSocket messages to the vulnerable server, leading to potential information disclosure.
OpenCVE Enrichment