Websocket Server Vulnerability in GeoVision Software
CVE-2026-57267
8.3HIGH
What is CVE-2026-57267?
The GeoWebPlayer, an integral addon for GeoVision software packages such as GV-VMS and GV-Cloud, features a websocket server that enhances web-interface capabilities. However, this server’s command handling mechanism is flawed, as it fails to validate the range of the index parameter for numerous commands. This oversight allows attackers to exploit the websocket server by sending out-of-bounds index values, potentially leading to unauthorized access to sensitive data or system functions.
Affected Version(s)
GeoWebPlayer Windows V1.1.1.0
GeoWebPlayer Windows V1.1.3.0
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
