SQL Client — possible Security Feature Bypass
Publication Date: 12.11.2024
Last Update: 12.11.2024
Current Version: v1.0
CVE Number: CVE-2024-0056
CVSS v3.1 Base Score: 8.7
SUMMARY
Milestone has released a software update for Milestone VMS, which fixes a security vulnerability in a third-party component with a possible Security Feature Bypass where an attacker can perform an adversary-in-the-middle attack between SQL Client and SQL Server. The vulnerability is registered under CVE-2024-0056.
AFFECTED PRODUCTS AND SOLUTIONS
Affected Products and Versions | Remediation |
|---|---|
XProtect TBD 2023 R3 | Apply the provided hotfix. |
XProtect TBD 2023 R2 | Apply the provided hotfix. |
XProtect TBD 2023 R1 | Apply the provided hotfix. |
XProtect TBD 2022 R3 | Apply the provided hotfix. |
XProtect TBD 2022 R2 | Apply the provided hotfix. |
XProtect TBD 2022 R1 | Apply the provided hotfix. |
Note: A complete list of XProtect VMS cumulative patches is available in KB 34370.
WORKAROUNDS AND MITIGATIONS
To mitigate the issue, we highly recommend applying the provided hotfixes or updating to the latest version.
If, for any reason, it is not possible, you should secure your network as for the successful exploitation the attacker needs to be able to intercept the network communication between the SQL server and any of the clients.
GENERAL SECURITY RECOMMENDATIONS
As a general security measure Milestone strongly recommends protecting network access to affected products with appropriate mechanisms. It is advised to follow the security practices recommended in the Milestone Hardening guide to run the devices in a protected IT environment.
PRODUCT DESCRIPTION
The Management Server is the central component of the VMS system. It stores the configuration of the surveillance system in an SQL database, either on a SQL Server on the Management Server computer itself or on a separate SQL Server on the network. It also handles user authentication, user permissions, the rule system and more. To improve system performance, you can run several Management Servers as a Milestone Federated Architecture™. The Management Server runs as a service and is typically installed on a dedicated server.
Users connect to the Management Server for initial authentication, then transparently to the Recording Servers for access to video recordings, etc.
The Identity Provider app pool (IDP) is a system entity that creates, maintains, and manages identity information for users.
Identity Provider also provides authentication and registration services to other applications or services. Identity Provider runs in the IIS as a part of the Management Server using the same SQL Server with a separate database and is responsible for creating and handling OAuth communication tokens that services use when communicating (Surveillance_IDP).
The XProtect Mobile Server handles logins to the system from the XProtect Mobile Client or XProtect Web Client.
An XProtect Mobile Server distributes video streams from Recording Servers to the XProtect Mobile Client or XProtect Web Client. This offers a secure setup where Recording Servers are never connected to the internet. When an XProtect Mobile Server receives video streams from Recording Servers, it also handles the complex conversion of codecs and formats, allowing the streaming of video on the mobile device.
The Event Server handles various tasks related to events, alarms, and maps and perhaps also third-party integrations via the MIP SDK.
The Recording Server is responsible for communicating with the network cameras and video encoders, recording the retrieved audio and video as well as providing client access to both live and recorded audio and video. The Recording Server is also responsible for communicating with other Milestone products connected via the Milestone Interconnect technology.
The Management Client is a feature-rich administration client for configuration and day-to-day management of the system. It's available in several languages.
Typically installed on the surveillance system administrator's workstation or similar.
XProtect Smart Client is a desktop application designed to help you manage your IP surveillance cameras. It provides intuitive control over security installations by giving users access to live and recorded video, instant control of cameras and connected security devices, and the ability to make advanced searches for recordings and metadata.
The Log Server stores all log messages for the entire system in a SQL Server database. This log messages database can exist on the same SQL Server as the Management Server's system configuration database or on separate SQL Server. The Log Server is typically installed on the same machine as the Management Server but can also be installed on a separate server machine for increased performance of the Management and Log Servers.
The Server Configurator is used to select certificates on local servers for encrypted communication and register server services to make them qualified to communicate with the servers.
The following types of servers in XProtect VMS need certificates for secure communication:
Management Servers
Recording Servers
Event Servers
Mobile Servers
These servers work with the Server Configurator to manage secure communications. Use the Server Configurator to set whether or not the XProtect servers use secure encrypted communications and to manage the certificates that the XProtect servers use.
The Server Configurator is installed by default on any computer that hosts an XProtect server.
Milestone Diagnostics Tool is a system diagnostics tool that gathers and displays detailed information about your system setup. This information includes, but is not limited to, ports, camera drivers, software versions and hardware information. You can also find a list of all cameras that have been added to the system, including the specific device model and camera manufacturer, no matter the size of the system setup.
VULNERABILITY CLASSIFICATION
The vulnerability classification has been performed by using the CVSS scoring system in version 3.1 (CVSS v3.1) (https://www.first.org/cvss). The CVSS environmental score is specific to the customer’s environment and will impact the overall CVSS score. The environmental score should therefore be individually defined by the customer to accomplish final scoring.
At the time of advisory publication, no public exploitation of this security vulnerability was known. Milestone confirms the security vulnerability and provides mitigations to resolve the security issue.
CVSS v3.1 Base Score 8.7
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
ADDITIONAL INFORMATION
For further inquiries on security vulnerabilities in Milestone Systems products, please contact Milestone PSIRT Team: psirt@milestonesys.com.
Additional information about the vulnerability can be found in the Microsoft’s security advisory.
HISTORY DATA
V1.0 (12.11.2024): Publication Date
Article Number
000003714