Security Advisories
Security Advisory Notifications
Subscribe to receive immediate notifications for critical vulnerabilities and security updates affecting GVision Italia products. Advisories are published per ISO/IEC 29147 guidelines.
Resolved Security Advisories 2026
GV-ASManager Vulnerability
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-AS1620 Controller Vulnerabilities
2 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-IP Device Utility Vulnerability
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-LPC2011 / LPC2211 Vulnerabilities
10 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-GeoWebPlayer Vulnerabilities
18 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-VMS V20 and GV-Cloud Vulnerability
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-I/O Box 4E Vulnerabilities
8 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-ASManager Web Vulnerabilities
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-IP Device Utility Vulnerability
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-VMS Web Vulnerabilities
3 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-LPC2011 / LPC2211 Vulnerabilities
6 vulnerabilities published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
GV-Edge Recording Manager Vulnerability
1 vulnerability published through the CVE Program. The corrected release is included in the certified EU packages available in the Certification Portal.
Certified EU packages are available in the Certification Portal.
Resolved Security Advisories 2025
GV-ASManager Software Vulnerabilities – Patches Distributed
Multiple vulnerabilities were identified in the GeoVision ASManager software (Windows application) affecting authentication and session management. As Terminal Manufacturer, GVision Italia coordinated the patch distribution for EU deployments and provided additional hardening guidelines including enhanced input validation, secure session handling, and NIS2-compliant logging mechanisms.
Fixed in version 6.2.0
Download available from GeoVision official site or GVision Italia portal
GV-ASManager Multiple Security Vulnerabilities – Software Update Required
Critical security vulnerabilities affecting GeoVision ASManager web application (ASWeb component) including broken access control, CSRF, information disclosure, and request method tampering. GVision Italia, acting as Terminal Manufacturer for the EU market, coordinated the patch distribution and implemented comprehensive security configurations including: Guest account hardening, enhanced authorization checks at multiple layers, input sanitization per OWASP guidelines, and additional EU-specific security controls mandated by the Cyber Resilience Act.
Fixed in version 6.2.0
Security configuration package available for EU deployments
✓ Closed Security Notices 2026
Broadcom NetXtreme bnxt_en Driver: Inventory Assessment Completed
Following the publication of CVE-2026-23041 (null pointer dereference in the Linux kernel
bnxt_en driver,
Broadcom NetXtreme chipset family, kernel < 6.13.3), GVision Italia initiated a full inventory
assessment of all distributed devices, including custom embedded units produced for enterprise customers
under confidential supply agreements.
The assessment, completed in March 2026, determined that none of the
devices within GVision Italia’s distributed inventory are affected by this vulnerability.
No Broadcom NetXtreme chipset subject to the vulnerable bnxt_en
PTP initialization path was found in any product line, including catalogue products and
non-catalogue enterprise devices.
Custom embedded devices produced for enterprise clients (non-catalogue)
Assessment method: hardware inventory review + kernel driver audit
No customer action required · Notice closed
Closed notices represent completed assessments with a “Not Affected” or resolved determination. · Security Policy
- Immediate response to vulnerability disclosures from GeoVision Inc. CNA
- Comprehensive testing of all patches in EU operational environments
- Additional security configurations per NIS2 Directive and Cyber Resilience Act requirements
- Complete audit trail and documentation for all software modifications
- Coordinated disclosure within 90 days per ISO/IEC 29147 guidelines