CVE-2018-7891
30.04.2018, 15:29
The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
milestonesys | xprotect | 10.0.a ≤ 𝑥 ≤ 12.1a |
milestonesys | xprotect | 10.0.a ≤ 𝑥 ≤ 12.1a |
milestonesys | xprotect | 10.0.a ≤ 𝑥 ≤ 12.1a |
milestonesys | xprotect | 10.0.a ≤ 𝑥 ≤ 12.1a |
milestonesys | xprotect | 10.0.a ≤ 𝑥 ≤ 12.1a |
siemens | siveillance_vms | 𝑥 < 10.0a |
siemens | siveillance_vms | 𝑥 < 10.1a |
siemens | siveillance_vms | 𝑥 < 10.2b |
siemens | siveillance_vms | 𝑥 < 11.1a |
siemens | siveillance_vms | 𝑥 < 11.2a |
siemens | siveillance_vms | 𝑥 < 12.1a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References