PT-2018-18309 · Milestone · Milestone Xprotect Video Management

Publicado

1999-01-01

·

Atualizado

2018-06-13

·

CVE-2018-7891

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) versions 2016 R1 (10.0.a) through 2018 R1 (12.1a)
Description: The issue concerns .NET Remoting endpoints that are vulnerable to deserialization attacks, which can result in remote code execution.
Recommendations: For versions 2016 R1 (10.0.a) through 2018 R1 (12.1a), consider disabling the .NET Remoting endpoints as a temporary workaround until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7891
DOTNETREMOTINGCHECK

Produtos afetados

Milestone Xprotect Video Management