CVE-2026-12488: GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.
A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GV-VMS V20 (GV-Cloud)to a version that resolves this vulnerability.Fixed in V20.1.0 - Compensating control
Mitigate potential denial-of-service and server impersonation risk until the GV-VMS V20 GV-Cloud update is applied by limiting exposure of GV-Cloud network services to trusted clients/hosts only (e.g., via network ACL/firewall rules).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12488?
The severity of CVE-2026-12488 is medium with a score of 6.2.
How do I fix CVE-2026-12488?
To fix CVE-2026-12488, you should update to the latest version of GeoVision GV-VMS available from the official vendor.
What impact does CVE-2026-12488 have on systems?
CVE-2026-12488 can lead to a denial of service if exploited by a specially crafted network request.
Who is affected by CVE-2026-12488?
GeoVision GV-VMS V20 version 20.0.2 is affected by CVE-2026-12488 if it utilizes the GV-Cloud functionality.
What kind of attacks can CVE-2026-12488 facilitate?
CVE-2026-12488 can facilitate denial of service attacks and allow an attacker to impersonate a legitimate server.