000001392 Milestone Mobile Server authentication bypass vulnerability
SUMMARY
Milestone has released a software update for the Milestone VMS to address a security vulnerability that could allow a bypass of the authentication process in the Mobile Server.
AFFECTED PRODUCTS AND VERSIONS
- XProtect Mobile Server 2022 R2
Remediation: Please apply the provided hotfix — XProtect 2022 R2 cumulative patch (KB 45010)
- XProtect Mobile Server 2022 R3
Remediation: Please apply the provided hotfix — XProtect 2022 R3 cumulative patch (KB 50200)
WORKAROUNDS AND MITIGATIONS
There is a possible workaround to mitigate the issue:
In the Management Client, use the left-hand menu to navigate to Servers → Mobile Servers.
Select your Mobile Server, then open the General tab.
In the Features section, enable “Deny the built-in Administrators role access to the mobile servers” and then Save your changes.
Now, Active Directory accounts that are members of the Administrators group will not be able to log in. (Note: It is still recommended to apply the patch even if you implement this workaround!)
GENERAL SECURITY RECOMMENDATIONS
As a general security measure Milestone strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow the security practices recommended in the Milestone Hardening Guide to run the devices in a protected IT environment.
PRODUCT DESCRIPTION
The XProtect Mobile server handles logins to the system from the XProtect Mobile client or XProtect Web Client.
An XProtect Mobile server distributes video streams from recording servers to the XProtect Mobile client or XProtect Web Client. This offers a secure setup where recording servers are never connected to the internet. When an XProtect Mobile server receives video streams from recording servers, it also handles the complex conversion of codecs and formats, allowing the streaming of video on the mobile device.
VULNERABILITY CLASSIFICATION
The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score is specific to the customer’s environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring.
At the time of advisory publication, no public exploitation of this security vulnerability was known. Milestone confirms the security vulnerability and provides mitigations to resolve the security issue.
CVSS v3.1 Base Score 9.4
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
ADDITIONAL INFORMATION
For further inquiries on security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/support/tools-and-references/cyber-security/
HISTORY DATA
V1.0 (21.10.2022): Publication Date
Article Number
000001398