CVE-2024-12569 — sensitive information in the drivers' log file
Publication Date: 19.12.2024
Last Update: 19.12.2024
Current Version: v1.0
CVE Number: CVE-2024-12569
CVSS v4.0 Score: 5.2 / Medium
CVSS v3.1 Score: 7.8 / High
SUMMARY
Milestone has released a new version of the XProtect Device Pack to address a security vulnerability in third-party cameras' drivers. This vulnerability logs credentials used during failed authentications.
AFFECTED PRODUCTS AND SOLUTIONS
Affected Products and Versions Remediation:
XProtect Device Driver 13.4a and earlier - Install the latest Device Pack.
WORKAROUNDS AND MITIGATIONS
To reduce risk, we strongly advise you to install the latest XProtect Device Pack, which provides the most current device drivers.
If it is not possible to update, please monitor log files at: %PROGRAMDATA%\XProtect Recording Server\Logs\Drivers for any exposed credentials.
GENERAL SECURITY RECOMMENDATIONS
Milestone strongly recommends securing network access to affected products using appropriate controls. Please follow the security best practices outlined in the Milestone Hardening Guide to ensure your devices operate in a secure IT environment.
PRODUCT DESCRIPTION
The XProtect Device Pack is a collection of drivers that enables your XProtect VMS system to interact with hardware devices. Installed with the XProtect VMS system on the Recording Server, the latest Device Pack can be obtained by manually checking for updates and installing the latest version. After installation, you can update your Device Pack by visiting the downloads section on the Milestone website (https://www.milestonesys.com/downloads/) to retrieve the appropriate installation file.
VULNERABILITY CLASSIFICATION
This vulnerability assessment uses the CVSS scoring system version 4.0 (CVSS v4.0) (https://www.first.org/cvss)). The CVSS environmental score, determined by each customer, will affect the overall CVSS score and should be individually calculated to achieve final scoring.
No public exploitation of this security vulnerability was known at the time this advisory was published. Milestone confirms the vulnerability and offers mitigations to address the issue.
CVSS v4.0 Score: 5.2 / Medium
CVSS Vector CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
CVSS v3.1 Score: 7.8 / High CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
ADDITIONAL INFORMATION
If you need more information about security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team at PSIRT@milestonesys.com.
HISTORY DATA
V1.0 (12.12.2024): Publication Date
V1.1 (09.04.2025): CVSS 3.1 Scoring added
Article Number
000003545