Missing encryption between Identity Server and SQL Server
Publication Date: 21.03.2022
Last Update: 21.03.2022
Current Version: v0.1
CVSS v3.1
Base Score: 7.4
SUMMARY
Milestone has released a software update for the XProtect® VMS which fixes a security vulnerability that enabled unencrypted communication between the Identity Server and SQL server. This vulnerability might result in an attacker being able to sniff the traffic between those servers.
Milestone recommends applying the hotfixes at the earliest opportunity.
AFFECTED PRODUCTS AND SOLUTIONS
Affected Products and Versions | Remediation |
|---|---|
XProtect VMS 2022 R1 | Apply the hotfix provided. |
WORKAROUNDS AND MITIGATIONS
There are no specific workarounds and mitigations that customers can apply to reduce the risk.
GENERAL SECURITY RECOMMENDATIONS
As a general security measure, Milestone strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow the recommendations included in the Milestone Hardening Guide security practices to run the devices in a protected IT environment.
PRODUCT DESCRIPTION
The Identity Provider app pool (IDP) is a system entity that creates, maintains, and manages identity information for users.
Identity Provider also provides authentication and registration services to relying applications or services. Identity Provider runs in the IIS as a part of the Management Server using the same SQL Server with a separate database and is responsible for creating and handling OAuth communication tokens that services use when communicating (Surveillance_IDP).
VULNERABILITY CLASSIFICATION
The vulnerability classification has been carried out using the CVSS scoring system version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score is tailored to the customer’s environment, impacting the total CVSS score. Therefore, the environmental score should be defined individually by the customer to complete the final scoring.
Vulnerability
Milestone has released a software update for the XProtect VMS that addresses a security vulnerability allowing unencrypted communication between the Identity Server and SQL server. This issue could enable an attacker to obtain confidential information from the device hosting these servers.
CVSS v3.1 Base Score 7.4
CVSS Vector CVSS:3.1AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CWE
CWE-311: Missing Encryption of Sensitive Data
Steps to apply the hotfix
- Install the 2022 R1 Cumulative patch installer (KB 40000) for the Management Server and follow the instructions in the installer wizard.
- The vulnerability will be permanently addressed in the XProtect 2022 R2 release.
ADDITIONAL INFORMATION
For further inquiries on security vulnerabilities in Milestone Systems products, please contact the Milestone PSIRT Team: https://www.milestonesys.com/da/support/tools-and-references/cyber-security/
HISTORY DATA
V1.0 (21.03.2022): Publication Date
Article Number
000003975