PatchSiren cyber security CVE debrief
CVE-2026-42363 GeoVision Inc. CVE debrief
An insufficient encryption vulnerability in GeoVision GV-IP Device Utility 9.0.5 allows credential theft via passive network monitoring. The utility broadcasts privileged commands over UDP with username and password encrypted using a Blowfish-derived protocol, but the symmetric encryption key is transmitted in the same packet. An attacker on the same LAN can capture broadcast traffic and decrypt credentials using knowledge of the algorithm, gaining full device control including configuration changes and factory reset capability.
- Vendor
- GeoVision Inc.
- Product
- GV-IP Device Utility
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-27
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-04-27
- Advisory updated
- 2026-05-19
Who should care
Organizations using GeoVision IP cameras, access control, or other GV-series devices managed through the GV-IP Device Utility, particularly those with flat network topologies where IoT management traffic shares broadcast domains with user devices.
Technical summary
The GeoVision GV-IP Device Utility 9.0.5 transmits device credentials in UDP broadcast packets using a Blowfish-derived encryption scheme where the symmetric key is included in the same packet. This security-through-obscurity design allows any network observer to decrypt captured traffic and recover plaintext credentials. Successful exploitation grants administrative control over affected GeoVision devices.
Defensive priority
critical
Recommended defensive actions
- Segment IoT device management traffic to isolated VLANs with no guest or untrusted device access
- Monitor for UDP broadcast traffic on ports used by GeoVision device discovery and management tools
- Implement network access control (NAC) to restrict which endpoints can communicate with GeoVision devices
- Audit and rotate credentials on all GeoVision devices managed by affected utility versions
- Contact GeoVision for patched utility version and apply security updates when available
- Consider disabling broadcast-based device discovery in favor of unicast or certificate-based authentication where supported
Evidence notes
Vulnerability disclosed via NVD with CVSS 9.3 (CRITICAL). Source references include Talos Intelligence vulnerability reports and GeoVision security page. NVD status marked as 'Deferred' as of 2026-05-19.
Official resources
-
CVE-2026-42363 CVE record
CVE.org
-
CVE-2026-42363 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
0df08a0e-a200-4957-9bb0-084f562506f9
-
Source reference
0df08a0e-a200-4957-9bb0-084f562506f9
2026-04-27