MEDIUM
CVE-2026-12488
CVSS
6.2
Description
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.
A specially crafted network request can lead to a denial of service. An attacker can impersonate the legitimate server to trigger this vulnerability.
Summary dbcve.org
Memory corruption vulnerability in the GV-Cloud component of GeoVision GV-VMS V20 20.0.2 allows an attacker impersonating the legitimate server to send specially crafted network requests, causing a denial of service.
Mitigation
Apply vendor-provided patch for GV-VMS V20 20.0.2; implement TLS/certificate validation for GV-Cloud communications to prevent server impersonation attacks.
Weakness (CWE)
CWE-121
Stack-based Buffer Overflow
EPSS Score
0.34%
Probability of exploitation in next 30 days
26.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.