Skip to main content

Milestone Security Advisory

OpenSSL vulnerabilities (CVE-2022-3602 and CVE-2022-3786) impact on the XProtect VMS

Last Updated: 1 minute read
LanguageEnglish

Publication Date: 04-Nov-2022  

Last Update: 04-Nov-2022  

Current Version: v1.0   

SUMMARY   

Our initial investigation does not show any severe impact on our products and installations.  

Versions of XProtect VMS before v. 2022 R3 are not affected. 

In XProtect VMS 2022 R3 (22.3a and 22.3b), the 3.0.5 version of the OpenSSL library is present in the LPR Server and the Open Network Bridge. However, potential successful exploitation requires attackers to already have control over a Certificate Authority trusted by the XProtect servers and be able to impact network communication between them, making the attack vector highly improbable. 

The OpenSSL libraries will be updated to the latest versions in upcoming XProtect releases. 

AFFECTED PRODUCTS AND SOLUTIONS 

Affected Products and Versions 

Remediation 

XProtect LPR 2022 R3 

None 

Milestone Open Network Bridge 2022 R3 

None 

GENERAL SECURITY RECOMMENDATIONS 

Milestone strongly recommends securing network access to affected products with suitable mechanisms as a general security practice. Follow the security guidelines detailed in the Milestone Hardening Guide to operate devices in a safeguarded IT environment. 

PRODUCT DESCRIPTION 

XProtect LPR provides video-based content analysis (VCA) and vehicle license plate recognition, integrating with your surveillance system and XProtect Smart Client. 

The Milestone Open Network Bridge is an open, ONVIF-compliant interface that standardizes video sharing from XProtect VMS systems to other IP-based security systems, enabling law enforcement, surveillance centers, and similar organizations (referred to as ONVIF clients) to access live and recorded video streams from XProtect VMS systems for central monitoring solutions. These video streams are transmitted as RTSP streams over the Internet. 

ADDITIONAL INFORMATION 

For additional questions regarding security vulnerabilities in Milestone Systems products, contact the Milestone PSIRT Team: https://www.milestonesys.com/psirt. 

HISTORY DATA  

V1.0 (04-Nov-2022): Publication Date

Article Number