CVE-2024-3506 Camera Driver possible Buffer Overflow
Publication Date: 08.10.2024
Last Update: 08.10.2024
Current Version: v1.0
CVE Number: CVE-2024-3506
CVSS v3.1 Base Score: 6.7 Medium
CVSS v4.0 Score: 7.3 / High
SUMMARY
Milestone has released a new version of the XProtect Device Pack that fixes a security vulnerability in selected cameras’ drivers involving a potential buffer overflow in specific conditions. This vulnerability may make it possible for an attacker to execute code with Recording Server user permissions. At this time, no public PoC or exploit is known.
AFFECTED PRODUCTS AND SOLUTIONS
Affected Products and Versions | Remediation |
|---|---|
XProtect Device Driver 13.1a or earlier | Install the latest Device Pack |
WORKAROUNDS AND MITIGATIONS
To mitigate the issue, we highly recommend installing the latest XProtect Device Pack which contains the most up-to-date device drivers. (At the time of this article, this is Device Pack 13.3a.) If, for any reason, this is not possible, you should proceed with caution when adding a new camera and scan only IP addresses that are confirmed to be valid and trusted devices.
GENERAL SECURITY RECOMMENDATIONS
As a general security measure, Milestone strongly suggests protecting network access to affected products with appropriate mechanisms. It is advised to follow the security practices recommended in the Milestone Hardening guide to run the devices in a protected IT environment.
PRODUCT DESCRIPTION
The XProtect Device Pack is a set of drivers installed with your XProtect system to enable interaction with your devices. The Device Pack is installed on the Recording Server and comes automatically with the XProtect VMS system installation. To obtain the latest Device Pack, manually check for newer versions that can be downloaded and installed. To update your Device Pack after installation, visit the download section on the Milestone website (https://www.milestonesys.com/downloads/) and download the appropriate installation file.
VULNERABILITY CLASSIFICATION
The vulnerability classification was carried out using the CVSS scoring system, version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score must be tailored by each customer according to their specific environment, as it affects the overall CVSS score. Therefore, customers should individually define the environmental score to ensure accurate final scoring. At the advisory's publication date, there was no known public exploitation of this security vulnerability. Milestone acknowledges the security vulnerability and provides mitigations to address the issue.
CVSS v3.1 Base Score: 6.7
CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
CVSS v4.0 Score: 7.3 / High
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L
ADDITIONAL INFORMATION
For further questions about security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/psirt
HISTORY DATA V1.0 (08.10.2024):
Publication Date: 01.10.2024
Article Number
000003726