Impact
The GeoWebPlayer websocket server processes the connectionInfo command by copying JSON data into fixed-size buffers without enforcing length limits. This flaw presents as a stack-based buffer overflow that an attacker can trigger by sending a crafted JSON string. If the overflow is successfully invoked, it can corrupt critical control information on the stack and may lead to arbitrary code execution on the host system.
Affected Systems
GeoVision GeoWebPlayer version 1.1.1.0 in both 64‑bit and Windows builds is affected. The component is typically installed as an addon within GeoVision software suites such as GV‑VMS and GV‑Cloud to provide websocket‑based camera connectivity. The vendor has issued a patched release, GeoWebPlayer V1.1.3.0, which resolves the overflow.
Risk and Exploitability
The CVSS score of 8.3 categorizes the vulnerability as high severity. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. The likely can send messages to the websocket server on the host can craft a malicious connectionInfo command, potentially enabling attacker‑controlled code execution.
OpenCVE Enrichment