PT-2018-18309 · Milestone · Milestone Xprotect Video Management
Publicado
1999-01-01
·
Atualizado
2018-06-13
·
CVE-2018-7891
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) versions 2016 R1 (10.0.a) through 2018 R1 (12.1a)
Description:
The issue concerns .NET Remoting endpoints that are vulnerable to deserialization attacks, which can result in remote code execution.
Recommendations:
For versions 2016 R1 (10.0.a) through 2018 R1 (12.1a), consider disabling the .NET Remoting endpoints as a temporary workaround until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Milestone Xprotect Video Management