Milestone Event Server — possible Remote Code Execution by an authenticated user
CVSS v3.1 Base Score: 9.9 SUMMARY Milestone has released a software update for Milestone VMS, which fixes a security vulnerability with a possible Remote Code Execution by an authenticated user on the Event Server service. AFFECTED PRODUCTS AND SOLUTIONS
Affected Products and Versions | Remediation |
|---|---|
XProtect Event Server 2023 R1 | Apply the hotfix provided: XProtect 2023 R1 cumulative patch (KB 51000) |
XProtect Event Server 2022 R3 | Apply the hotfix provided: XProtect 2022 R3 cumulative patch (KB 50200) |
XProtect Event Server 2022 R2 | Apply the hotfix provided: XProtect 2022 R2 cumulative patch (KB 45010) |
XProtect Event Server 2022 R1 | Apply the hotfix provided: XProtect 2022 R1 cumulative patch (KB 40000) |
XProtect Event Server 2021 R2 | Apply the hotfix provided: XProtect 2021 R2 cumulative patch (KB 39500) |
XProtect Event Server 2021 R1 | Apply the hotfix provided: XProtect 2021 R1 cumulative patch (KB 36500) |
XProtect Event Server 2020 R3 | Apply the hotfix provided: XProtect 2020 R3 cumulative patch (KB 28000) |
XProtect Event Server 2020 R2 | Apply the hotfix provided: XProtect 2020 R2 cumulative patch (KB 22900) |
WORKAROUNDS AND MITIGATIONS There are currently no known workarounds. Please update your system. GENERAL SECURITY RECOMMENDATIONS As a general security measure Milestone strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow the security practices recommended in the Milestone Hardening Guide to run the devices in a protected IT environment. PRODUCT DESCRIPTION The event server handles various tasks related to events, alarms, and maps and perhaps also third-party integrations via the MIP SDK. VULNERABILITY CLASSIFICATION The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score is specific to the customer’s environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring. At the time of advisory publication, no public exploitation of this security vulnerability was known. Milestone confirms the security vulnerability and provides mitigations to resolve the security issue. CVSS v3.1 Base Score 9.9 CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H ADDITIONAL INFORMATION For further inquiries on security vulnerabilities in Milestone Systems products, please contact Milestone PSIRT Team: https://www.milestonesys.com/psirt HISTORY DATA V1.0 (09.05.2023): Publication Date
Article Number
000001246