Websocket Server Vulnerability in GeoWebPlayer by GeoVision
CVE-2026-13132
8.3HIGH
What is CVE-2026-13132?
GeoWebPlayer, often referred to as 'Web Plugin' in the GV-VMS documentation, acts as an addon for various GeoVision software. This component creates a websocket server that is essential for extending the functionalities of the web interfaces provided by the GeoVision software. However, this websocket server has a security flaw where the index values it accepts for executing commands are not adequately validated, allowing potential out-of-bounds access. Such access can lead to unauthorized manipulation of critical arrays and functions within the system, posing a significant risk to the integrity and stability of the affected software.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
