CVE-2025-1688

Severity CVSS v4.0:
MEDIUM
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
15/04/2025
Last modified:
15/04/2025

Description

Milestone Systems has discovered a<br /> security vulnerability in Milestone XProtect installer that resets system<br /> configuration password after the upgrading from older versions using specific<br /> installers.<br /> <br /> <br /> <br /> The system configuration<br /> password is an additional, optional protection that is enabled on the<br /> Management Server.<br /> <br /> <br /> To mitigate the issue, we highly recommend updating system configuration password via GUI with a standard procedure.<br /> <br /> <br /> <br /> Any system upgraded with<br /> 2024 R1 or 2024 R2 release installer is vulnerable to this issue.<br /> <br /> <br /> <br /> Systems upgraded from 2023<br /> R3 or older with version 2025 R1 and newer are not affected.