« Volver al listado

CVE-2026-57268

Estado: AplazadaAlta (8.3)—

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.

The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.

Leer descripción completaMostrar menos

### saveVideo command index-out-of-bound

When sending the `saveVideo` command, the `index` field is extracted from the websocket message [1]. Then without checking the range of the index, it is used to trigger a CriticalSection ([2]) and releases it [3]. The release function call ([3]) is executed using a function pointer which will be read out of bounds potentially leading to code execution:

Detalles técnicos trazas, registros y código del informe original
     v6 = get_entry(a2, "index");

      result = json_is_value_int(v6);

      if ( (_BYTE)result )

      {

        v8 = get_entry(a2, "index");

        index = json_value_to_int(&v8->value);  // [1]

        result = CCriticalSection::EnterCritSection(&this->crit_sections[index]);  //[2]

        if ( result )

        {

          if ( this->array_of_IPCams[index] )

          {

            if ( this->array_of_IPCams[index]->field_20 )

              do_PostMessageA((CViewer *)this->array_of_IPCams[index], 0x111u, 0x139Fu, v11);

          }

          return (*(int (__thiscall **)(CCriticalSection *))(this->crit_sections[index].vtbl + 20))(&this->crit_sections[index]); //[3]

        }

      }

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R (interacción del usuario: websocket desde navegador local) define T1203. Out-of-bounds en puntero vtbl permite ejecución arbitraria (T1059) y potencial escalada (T1068 si alcanza privilegios del servicio).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-57268",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-57268",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-02T12:35:11.850544Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
      "affectedData": [
        {
          "vendor": "GeoVision Inc.",
          "product": "GeoWebPlayer",
          "versions": [
            {
              "status": "affected",
              "version": "V1.1.1.0"
            },
            {
              "status": "unaffected",
              "version": "V1.1.3.0"
            }
          ],
          "platforms": [
            "Windows",
            "64 bit"
          ],
          "packageName": "GeoWebPlayer",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-02T04:17:12.467",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2026-2373",
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9"
    },
    {
      "url": "https://www.geovision.com.tw/cyber_security.php",
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
      "description": [
        {
          "lang": "en",
          "value": "CWE-129"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GeoWebPlayer (also called \"Web Plugin\" in the GV-VMS documentation and \"WS Player\" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly.\n\nThe Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound.\n\n\n### saveVideo command index-out-of-bound\n\nWhen sending the `saveVideo` command, the `index` field is extracted from the websocket message [1]. Then without checking the range of the index, it is used to trigger a CriticalSection ([2]) and releases it [3]. The release function call ([3]) is executed using a function pointer which will be read out of bounds potentially leading to code execution:\n\n\n\n\n\n     v6 = get_entry(a2, \"index\");\n\n      result = json_is_value_int(v6);\n\n      if ( (_BYTE)result )\n\n      {\n\n        v8 = get_entry(a2, \"index\");\n\n        index = json_value_to_int(&v8->value);  // [1]\n\n        result = CCriticalSection::EnterCritSection(&this->crit_sections[index]);  //[2]\n\n        if ( result )\n\n        {\n\n          if ( this->array_of_IPCams[index] )\n\n          {\n\n            if ( this->array_of_IPCams[index]->field_20 )\n\n              do_PostMessageA((CViewer *)this->array_of_IPCams[index], 0x111u, 0x139Fu, v11);\n\n          }\n\n          return (*(int (__thiscall **)(CCriticalSection *))(this->crit_sections[index].vtbl + 20))(&this->crit_sections[index]); //[3]\n\n        }\n\n      }"
    }
  ],
  "lastModified": "2026-07-02T16:51:29.583",
  "sourceIdentifier": "0df08a0e-a200-4957-9bb0-084f562506f9"
}