8.1

CVE-2018-7891

The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Milestonesys ≫ Xprotect SwEdition corporate Version >= 10.0.a <= 12.1a
Milestonesys ≫ Xprotect SwEdition essential+ Version >= 10.0.a <= 12.1a
Milestonesys ≫ Xprotect SwEdition expert Version >= 10.0.a <= 12.1a
Milestonesys ≫ Xprotect SwEdition express+ Version >= 10.0.a <= 12.1a
Milestonesys ≫ Xprotect SwEdition professional+ Version >= 10.0.a <= 12.1a
Siemens ≫ Siveillance Vms Version < 10.0a
Siemens ≫ Siveillance Vms Version < 10.1a
Siemens ≫ Siveillance Vms Version < 10.2b
Siemens ≫ Siveillance Vms Version < 11.1a
Siemens ≫ Siveillance Vms Version < 11.2a
Siemens ≫ Siveillance Vms Version < 12.1a
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.18% 0.897
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.securityfocus.com/bid/104120
Third Party Advisory
VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-457058.pdf
Third Party Advisory
Mitigation
https://supportcommunity.milestonesys.com/s/article/XProtect-VMS-NET-security-vulnerability-hotfixes-for-2016-R1-2018-R1?language=en_US
Vendor Advisory