CVE-2018-7891

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
30/04/2018
Last modified:
13/06/2018

Description

The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:milestonesys:xprotect:*:*:*:*:corporate:*:*:* 10.0.a (including) 12.1a (including)
cpe:2.3:a:milestonesys:xprotect:*:*:*:*:essential\+:*:*:* 10.0.a (including) 12.1a (including)
cpe:2.3:a:milestonesys:xprotect:*:*:*:*:expert:*:*:* 10.0.a (including) 12.1a (including)
cpe:2.3:a:milestonesys:xprotect:*:*:*:*:express\+:*:*:* 10.0.a (including) 12.1a (including)
cpe:2.3:a:milestonesys:xprotect:*:*:*:*:professional\+:*:*:* 10.0.a (including) 12.1a (including)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 10.0a (excluding)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 10.1a (excluding)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 10.2b (excluding)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 11.1a (excluding)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 11.2a (excluding)
cpe:2.3:a:siemens:siveillance_vms:*:*:*:*:*:*:*:* 12.1a (excluding)