A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32092 A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.
Fixes

Solution

To mitigate the issue, we highly recommend installing the XProtect Device Pack version 13.2a or later which contains the most up to date device drivers.


Workaround

If, for any reason, patching is not possible, you should proceed with caution when adding new cameras and scan only IPs which are confirmed to be valid and trusted devices.

History

Tue, 08 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Milestone Systems
Milestone Systems xprotect Vms
CPEs cpe:2.3:a:milestone_systems:xprotect_vms:*:*:*:*:*:*:*:*
Vendors & Products Milestone Systems
Milestone Systems xprotect Vms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 10:15:00 +0000

Type Values Removed Values Added
Description A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions.
Title Camera Driver possible Buffer Overflow
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Milestone

Published:

Updated: 2024-10-08T13:50:58.073Z

Reserved: 2024-04-09T07:18:37.878Z

Link: CVE-2024-3506

cve-icon Vulnrichment

Updated: 2024-10-08T13:50:39.657Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-08T10:15:04.417

Modified: 2024-10-10T12:56:30.817

Link: CVE-2024-3506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.