CVE-2024-40898: potential risk in SafeKit used by XProtect Management Server Failover (MSF)
Publication Date: 28-Oct-2025
Last Update: 28-Oct-2025
Current Version: v1.0
CVE Number: CVE-2024-40898
CVSS v3.x Score: 7.5 / HIGH
Applies To
XProtect Management Server Failover (MSF)
XProtect 2025 R3
Evidian SafeKit 7.5.2.16
Summary
XProtect 2025 R3 embeds SafeKit version 7.5.2.16, a version upgrade from 7.5.2.7, selected to maintain compatibility and avoid breaking changes introduced in newer SafeKit versions.
Important: The product might be potentially affected by CVE-2024-40898, though there is no known evidence of exploitation in MSF environments.
This vulnerability affects Apache’s mod_rewrite module, which is used in MSF’s (Management Server Failover) context. While the upgrade to 7.5.2.16 addresses many known CVEs, CVE-2024-40898 remains relevant and warrants attention.
Risk Assessment
CVE-2024-40898 may lead to:
Server-Side Request Forgery (SSRF)
NTLM hash leakage in Windows environments
The vulnerability does not require user interaction and may be exploitable depending on network configuration and access controls.
Mitigation Recommendations
To reduce exposure:
Block inbound traffic on port 9010 on cluster nodes, as rewrite rules redirect HTTP requests on 9010 to HTTPS on 9453 before authentication.
Alternatively, restrict traffic on ports 9010 and 9453 to only cluster nodes and require console client access via VPN endpoint on the cluster nodes.
Additional Notes
SafeKit 7.5.2.16 includes updated components:
Apache httpd 2.4.61
cURL 8.8.0
OpenSSL 1.1.1w
OpenSSL is used by MSF for HTTPS and encrypted node communication. No vulnerabilities were detected in Milestone’s internal report related to OpenSSL usage.
CVE-2024-40898 is addressed in SafeKit version 8.2, which includes Apache httpd 2.4.62. Milestone has already planned to upgrade to SafeKit 8.2 in a future release of XProtect.
Article Number
000001035