Skip to main content

Milestone Security Advisory

CVE-2024-12569 — sensitive information in the drivers' log file

Last Updated: 2 minute read
LanguageEnglish

Publication Date: 19.12.2024

Last Update: 19.12.2024

Current Version: v1.0

CVE Number: CVE-2024-12569

CVSS v4.0 Score: 5.2 / Medium

CVSS v3.1 Score: 7.8 / High 

SUMMARY

Milestone has released a new version of the XProtect Device Pack to address a security vulnerability in third-party cameras' drivers. This vulnerability logs credentials used during failed authentications. 

AFFECTED PRODUCTS AND SOLUTIONS

Affected Products and Versions Remediation: 

XProtect Device Driver 13.4a and earlier - Install the latest Device Pack. 

WORKAROUNDS AND MITIGATIONS

To reduce risk, we strongly advise you to install the latest XProtect Device Pack, which provides the most current device drivers. 

If it is not possible to update, please monitor log files at: %PROGRAMDATA%\XProtect Recording Server\Logs\Drivers for any exposed credentials. 

GENERAL SECURITY RECOMMENDATIONS

Milestone strongly recommends securing network access to affected products using appropriate controls. Please follow the security best practices outlined in the Milestone Hardening Guide to ensure your devices operate in a secure IT environment.

PRODUCT DESCRIPTION

The XProtect Device Pack is a collection of drivers that enables your XProtect VMS system to interact with hardware devices. Installed with the XProtect VMS system on the Recording Server, the latest Device Pack can be obtained by manually checking for updates and installing the latest version. After installation, you can update your Device Pack by visiting the downloads section on the Milestone website (https://www.milestonesys.com/downloads/) to retrieve the appropriate installation file. 

VULNERABILITY CLASSIFICATION

This vulnerability assessment uses the CVSS scoring system version 4.0 (CVSS v4.0) (https://www.first.org/cvss)). The CVSS environmental score, determined by each customer, will affect the overall CVSS score and should be individually calculated to achieve final scoring.

No public exploitation of this security vulnerability was known at the time this advisory was published. Milestone confirms the vulnerability and offers mitigations to address the issue.

CVSS v4.0 Score: 5.2 / Medium

CVSS Vector CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

CVSS v3.1 Score: 7.8 / High CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H 

ADDITIONAL INFORMATION

If you need more information about security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team at PSIRT@milestonesys.com.

HISTORY DATA

V1.0 (12.12.2024): Publication Date

V1.1 (09.04.2025): CVSS 3.1 Scoring added

Article Number

000003545