Skip to main content

Milestone Security Advisory

Arbitrary file access on the DLNA Server

Last Updated: 2 minute read
LanguageEnglish

Milestone has released a software update for the XProtect VMS which fixes a security vulnerability that allowed arbitrary file access on the XProtect DLNA server. This vulnerability might result in an attacker retrieving confidential information from the machine where the DLNA server is installed.

Milestone recommends applying the provided hotfixes at the earliest opportunity.

AFFECTED PRODUCTS AND SOLUTIONS

 Affected Products and Versions 

Remediation 

XProtect DLNA Server 2021 R1 

Apply the provided hotfix.

XProtect DLNA Server 2020 R3 

Apply the provided hotfix.

XProtect DNLA Server 2020 R2 

Apply the provided hotfix.

XProtect DNLA Server 2020 R1 

Apply the provided hotfix.

XProtect DNLA Server 2019 R3 

Apply the provided hotfix.

XProtect DNLA Server 2019 R2 

Apply the provided hotfix.

XProtect DNLA Server 2019 R1 

Apply the provided hotfix.

Download the universal hotfix — KB 39746.

WORKAROUNDS AND MITIGATIONS

Milestone has identified the following specific workarounds and mitigations that customers can use to reduce the risk:  

  • Disable the DLNA server if not in use.

  • Note: By default, the DLNA server is not installed with the other components of the Milestone XProtect VMS.

GENERAL SECURITY RECOMMENDATIONS

As a general security measure, Milestone strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow recommendations included in the Hardening guide security practices to run the devices in a protected IT environment.Hardening guide

PRODUCT DESCRIPTION

DLNA (Digital Living Network Alliance) is a standard for connecting multimedia devices. Electronic manufacturers get their products DLNA certified to ensure interoperability between different vendors and devices and thereby enable them to distribute video content.

Public displays and TVs are often DLNA certified and connected to a network. They can scan the network for media content, connect to the device, and request a media stream to their built-in media player. XProtect DLNA Server can be discovered by certain DLNA certified devices and deliver live video streams from selected cameras to DLNA certified devices with a media player.

VULNERABILITY CLASSIFICATION

The vulnerability classification has been performed by using the CVSS scoring system in version 3.0 (CVSS v3.0, https://www.first.org/cvss).  The CVSS environmental score is specific to the customer’s environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring.  Vulnerability By using a specially crafted URL, a user can read arbitrary files on the server that are outside the web server’s document directory. An unauthenticated attacker could exploit this issue to access sensitive information for subsequent attacks. CVSS v3.1                    Base Score 8.6  CVSS Vector                CVSS:3.1AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:U/RC:C CWE                             CWE-26: Path Traversal Steps to apply the hotfix Install the MilestoneXProtectDLNAServerInstaller_x64.exe and follow the instructions on the screen. 

ADDITIONAL INFORMATION

For further inquiries on security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/da/support/tools-and-references/cyber-security/ 

HISTORY DATA

V1.0 (09.Nov.2021):  Publication Date  

Article Number

000004101