WebSocket Server Vulnerability in GeoVision GeoWebPlayer Plugin
CVE-2026-57264
8.3HIGH
What is CVE-2026-57264?
The GeoWebPlayer, part of various GeoVision software packages, incorporates a WebSocket server that enhances the functionality of its web interfaces. However, it has a critical flaw where the server accepts commands from localhost without proper validation of the 'index' value used in these commands. This lack of validation can lead to out-of-bounds access of sensitive data and functionalities, potentially allowing unauthorized actions within the software. Users of products implementing GeoWebPlayer should be aware of this vulnerability and take appropriate action to mitigate risks.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
