PT-2024-7807 · Milestone Systems · Xprotect Device Pack
Published
2024-04-09
·
Updated
2024-10-10
·
CVE-2024-3506
CVSS v3.1
6.7
Medium
| Vector | AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Siveillance Video (formerly Siveillance VMS) versions (affected versions not specified)
XProtect Device Pack versions (affected versions not specified)
Description
The issue is related to a buffer overflow vulnerability due to the lack of size checking for input data. This could allow a remote attacker to execute arbitrary code under certain conditions. The vulnerability may also enable an attacker with internal network access to execute commands on the Recording Server.
Recommendations
For Siveillance Video (formerly Siveillance VMS), at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For XProtect Device Pack, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xprotect Device Pack