Metrics
Affected Vendors & Products
No advisories yet.
Solution
To mitigate the issue, we highly recommend upgrading to the latest version of XProtect VMS, or at least to version 2025 R2 or later. The other option (for versions 2023 R1 – 2025 R1) is to use the provided cumulative patches (Knowledee Base article no. 34370 XProtect VMS cumulative patches). If, for any reason it is not possible, we recommend auditing your role security settings and considering everyone with read-only access to the Management Server as having a full access to Webhooks configuration.
Workaround
No workaround given by the vendor.
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Milestone Systems
Milestone Systems xprotect Vms |
|
| Vendors & Products |
Milestone Systems
Milestone Systems xprotect Vms |
Tue, 16 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API. | |
| Title | XProtect MIP API Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Milestone
Published:
Updated: 2025-12-16T14:51:38.048Z
Reserved: 2025-01-29T13:24:34.734Z
Link: CVE-2025-0836
Updated: 2025-12-16T14:51:33.939Z
Status : Awaiting Analysis
Published: 2025-12-16T11:15:43.510
Modified: 2025-12-16T14:15:45.630
Link: CVE-2025-0836
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:09:22Z