CVE-2026-57271: GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.
pause command index-out-of-bound
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoVision GeoWebPlayer Websocket Serverto a version that resolves this vulnerability.Fixed in V1.1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57271?
The severity of CVE-2026-57271 is rated as high with a score of 8.3.
How do I fix CVE-2026-57271?
To fix CVE-2026-57271, users should update to the latest version of GeoWebPlayer that addresses the out-of-bounds read vulnerability.
What are the potential impacts of CVE-2026-57271?
The potential impacts of CVE-2026-57271 include unauthorized access to sensitive information due to an out-of-bounds read.
Who is affected by CVE-2026-57271?
Users of the GeoVision GeoWebPlayer Websocket Server are affected by CVE-2026-57271.
What is the nature of the vulnerability in CVE-2026-57271?
CVE-2026-57271 is an out-of-bounds read vulnerability that may allow attackers to access unintended memory regions.