Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32092 | A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions. |
Solution
To mitigate the issue, we highly recommend installing the XProtect Device Pack version 13.2a or later which contains the most up to date device drivers.
Workaround
If, for any reason, patching is not possible, you should proceed with caution when adding new cameras and scan only IPs which are confirmed to be valid and trusted devices.
Tue, 08 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Milestone Systems
Milestone Systems xprotect Vms |
|
| CPEs | cpe:2.3:a:milestone_systems:xprotect_vms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Milestone Systems
Milestone Systems xprotect Vms |
|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on Recording Server under strict conditions. | |
| Title | Camera Driver possible Buffer Overflow | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Milestone
Published:
Updated: 2024-10-08T13:50:58.073Z
Reserved: 2024-04-09T07:18:37.878Z
Link: CVE-2024-3506
Updated: 2024-10-08T13:50:39.657Z
Status : Awaiting Analysis
Published: 2024-10-08T10:15:04.417
Modified: 2024-10-10T12:56:30.817
Link: CVE-2024-3506
No data.
OpenCVE Enrichment
No data.
EUVD