PT-2024-7807 · Milestone Systems · Xprotect Device Pack

Published

2024-04-09

·

Updated

2024-10-10

·

CVE-2024-3506

CVSS v3.1

6.7

Medium

VectorAV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Siveillance Video (formerly Siveillance VMS) versions (affected versions not specified) XProtect Device Pack versions (affected versions not specified)
Description The issue is related to a buffer overflow vulnerability due to the lack of size checking for input data. This could allow a remote attacker to execute arbitrary code under certain conditions. The vulnerability may also enable an attacker with internal network access to execute commands on the Recording Server.
Recommendations For Siveillance Video (formerly Siveillance VMS), at the moment, there is no information about a newer version that contains a fix for this vulnerability. For XProtect Device Pack, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-09307
CVE-2024-3506

Affected Products

Xprotect Device Pack