CVE-2025-1688
Severity CVSS v4.0:
MEDIUM
Type:
CWE-311
Missing Encryption of Sensitive Data
Publication date:
15/04/2025
Last modified:
15/04/2025
Description
Milestone Systems has discovered a<br />
security vulnerability in Milestone XProtect installer that resets system<br />
configuration password after the upgrading from older versions using specific<br />
installers.<br />
<br />
<br />
<br />
The system configuration<br />
password is an additional, optional protection that is enabled on the<br />
Management Server.<br />
<br />
<br />
To mitigate the issue, we highly recommend updating system configuration password via GUI with a standard procedure.<br />
<br />
<br />
<br />
Any system upgraded with<br />
2024 R1 or 2024 R2 release installer is vulnerable to this issue.<br />
<br />
<br />
<br />
Systems upgraded from 2023<br />
R3 or older with version 2025 R1 and newer are not affected.
Impact
Base Score 4.0
5.50
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM