Skip to main content

Milestone Security Advisory

CVE-2024-3506 Camera Driver possible Buffer Overflow

Last Updated: 2 minute read
LanguageEnglish

Publication Date: 08.10.2024 

Last Update: 08.10.2024 

Current Version: v1.0 

CVE Number: CVE-2024-3506 

CVSS v3.1 Base Score: 6.7 Medium 

CVSS v4.0 Score: 7.3 / High 

SUMMARY 

Milestone has released a new version of the XProtect Device Pack that fixes a security vulnerability in selected cameras’ drivers involving a potential buffer overflow in specific conditions. This vulnerability may make it possible for an attacker to execute code with Recording Server user permissions. At this time, no public PoC or exploit is known.

AFFECTED PRODUCTS AND SOLUTIONS  

Affected Products and Versions

Remediation

XProtect Device Driver 13.1a or earlier

Install the latest Device Pack

WORKAROUNDS AND MITIGATIONS

To mitigate the issue, we highly recommend installing the latest XProtect Device Pack which contains the most up-to-date device drivers. (At the time of this article, this is Device Pack 13.3a.) If, for any reason, this is not possible, you should proceed with caution when adding a new camera and scan only IP addresses that are confirmed to be valid and trusted devices.

GENERAL SECURITY RECOMMENDATIONS

As a general security measure, Milestone strongly suggests protecting network access to affected products with appropriate mechanisms. It is advised to follow the security practices recommended in the Milestone Hardening guide to run the devices in a protected IT environment.Hardening guide

PRODUCT DESCRIPTION

The XProtect Device Pack is a set of drivers installed with your XProtect system to enable interaction with your devices. The Device Pack is installed on the Recording Server and comes automatically with the XProtect VMS system installation. To obtain the latest Device Pack, manually check for newer versions that can be downloaded and installed. To update your Device Pack after installation, visit the download section on the Milestone website (https://www.milestonesys.com/downloads/) and download the appropriate installation file.

VULNERABILITY CLASSIFICATION 

The vulnerability classification was carried out using the CVSS scoring system, version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score must be tailored by each customer according to their specific environment, as it affects the overall CVSS score. Therefore, customers should individually define the environmental score to ensure accurate final scoring. At the advisory's publication date, there was no known public exploitation of this security vulnerability. Milestone acknowledges the security vulnerability and provides mitigations to address the issue. 

CVSS v3.1 Base Score: 6.7

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

CVSS v4.0 Score: 7.3 / High

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L

ADDITIONAL INFORMATION 

For further questions about security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/psirt 

HISTORY DATA V1.0 (08.10.2024): 

Publication Date: 01.10.2024

Article Number

000003726