ID

VAR-201804-1326


CVE

CVE-2018-7891


TITLE

Milestone XProtect Video Management Vulnerability related to unreliable data deserialization in software

Trust: 0.8

sources: JVNDB: JVNDB-2018-004979

DESCRIPTION

The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution. Siemens Milestone XProtect Video Management Software is a set of video management software for managing surveillance video and other content. A remote attacker could use this vulnerability to execute code. Siemens Siveillance VMS is prone to a remote privilege-escalation vulnerability because it fails to properly sanitize user-supplied input. Failed exploit attempts may result in a denial of service condition

Trust: 2.43

sources: NVD: CVE-2018-7891 // JVNDB: JVNDB-2018-004979 // CNVD: CNVD-2018-10185 // BID: 104120

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-10185

AFFECTED PRODUCTS

vendor:siemensmodel:siveillance vmsscope:ltversion:10.0a

Trust: 1.0

vendor:milestonesysmodel:xprotectscope:lteversion:12.1a

Trust: 1.0

vendor:milestonesysmodel:xprotectscope:gteversion:10.0.a

Trust: 1.0

vendor:siemensmodel:siveillance vmsscope:ltversion:10.1a

Trust: 1.0

vendor:siemensmodel:siveillance vmsscope:ltversion:11.1a

Trust: 1.0

vendor:siemensmodel:siveillance vmsscope:ltversion:11.2a

Trust: 1.0

vendor:siemensmodel:siveillance vmsscope:ltversion:12.1a

Trust: 1.0

vendor:siemensmodel:siveillance vmsscope:ltversion:10.2b

Trust: 1.0

vendor:milestonemodel:xprotectscope:eqversion:2016 r1 (10.0.a) to 2018 r1 (12.1a)

Trust: 0.8

vendor:siemensmodel:siveillance vms video mobile applicationscope: - version: -

Trust: 0.8

vendor:siemensmodel:milestone xprotect video management software corporate r1 ,<=2018 r1scope:gteversion:2016

Trust: 0.6

vendor:siemensmodel:milestone xprotect video management software essential+ r1 ,<=2018 r1scope:gteversion:2016

Trust: 0.6

vendor:siemensmodel:milestone xprotect video management software expert r1 ,<=2018 r1scope:gteversion:2016

Trust: 0.6

vendor:siemensmodel:milestone xprotect video management software express+ r1 ,<=2018 r1scope:gteversion:2016

Trust: 0.6

vendor:siemensmodel:milestone xprotect video management software professional+ r1 ,<=2018 r1scope:gteversion:2016

Trust: 0.6

vendor:siemensmodel:siveillance vms r1scope:eqversion:20180

Trust: 0.3

vendor:siemensmodel:siveillance vms r2scope:eqversion:20170

Trust: 0.3

vendor:siemensmodel:siveillance vms r1scope:eqversion:20170

Trust: 0.3

vendor:siemensmodel:siveillance vms r3scope:eqversion:20160

Trust: 0.3

vendor:siemensmodel:siveillance vms r2scope:eqversion:20160

Trust: 0.3

vendor:siemensmodel:siveillance vms r1scope:eqversion:20160

Trust: 0.3

vendor:siemensmodel:siveillance vms r1 v12.1ascope:neversion:2018

Trust: 0.3

vendor:siemensmodel:siveillance vms r2 v11.2ascope:neversion:2017

Trust: 0.3

vendor:siemensmodel:siveillance vms r1 v11.1ascope:neversion:2017

Trust: 0.3

vendor:siemensmodel:siveillance vms r3 v10.2bscope:neversion:2016

Trust: 0.3

vendor:siemensmodel:siveillance vms r2 v10.1ascope:neversion:2016

Trust: 0.3

vendor:siemensmodel:siveillance vms r1 v10.0ascope:neversion:2016

Trust: 0.3

sources: CNVD: CNVD-2018-10185 // BID: 104120 // JVNDB: JVNDB-2018-004979 // NVD: CVE-2018-7891

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7891
value: HIGH

Trust: 1.0

NVD: CVE-2018-7891
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-10185
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-041
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2018-7891
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-10185
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-7891
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-10185 // JVNDB: JVNDB-2018-004979 // CNNVD: CNNVD-201805-041 // NVD: CVE-2018-7891

PROBLEMTYPE DATA

problemtype:CWE-502

Trust: 1.8

sources: JVNDB: JVNDB-2018-004979 // NVD: CVE-2018-7891

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-041

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 104120

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-004979

PATCH

title:XProtect VMS: .NET security vulnerability (hotfixes for 2016 R1 - 2018 R1)url:https://supportcommunity.milestonesys.com/s/article/XProtect-VMS-NET-security-vulnerability-hotfixes-for-2016-R1-2018-R1?language=en_US

Trust: 0.8

title:SSA-457058url:https://cert-portal.siemens.com/productcert/pdf/ssa-457058.pdf

Trust: 0.8

title:Patch for Siemens Milestone XProtect Video Management Software Deserialization Privilege Elevation Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/130133

Trust: 0.6

title:Milestone XProtect Video Management Software Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79784

Trust: 0.6

sources: CNVD: CNVD-2018-10185 // JVNDB: JVNDB-2018-004979 // CNNVD: CNNVD-201805-041

EXTERNAL IDS

db:NVDid:CVE-2018-7891

Trust: 3.3

db:SIEMENSid:SSA-457058

Trust: 1.9

db:BIDid:104120

Trust: 1.9

db:ICS CERTid:ICSA-18-128-02

Trust: 1.1

db:JVNDBid:JVNDB-2018-004979

Trust: 0.8

db:CNVDid:CNVD-2018-10185

Trust: 0.6

db:CNNVDid:CNNVD-201805-041

Trust: 0.6

sources: CNVD: CNVD-2018-10185 // BID: 104120 // JVNDB: JVNDB-2018-004979 // CNNVD: CNNVD-201805-041 // NVD: CVE-2018-7891

REFERENCES

url:https://supportcommunity.milestonesys.com/s/article/xprotect-vms-net-security-vulnerability-hotfixes-for-2016-r1-2018-r1?language=en_us

Trust: 2.2

url:http://www.securityfocus.com/bid/104120

Trust: 1.6

url:https://cert-portal.siemens.com/productcert/pdf/ssa-457058.pdf

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7891

Trust: 0.8

url:https://www.us-cert.gov/ics/advisories/icsa-18-128-02

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7891

Trust: 0.8

url:http://www.siemens.com/

Trust: 0.3

url:https://ics-cert.us-cert.gov/advisories/icsa-18-128-02

Trust: 0.3

url:https://cert-portal.siemens.com/productcert/txt/ssa-457058.txt

Trust: 0.3

sources: CNVD: CNVD-2018-10185 // BID: 104120 // JVNDB: JVNDB-2018-004979 // CNNVD: CNNVD-201805-041 // NVD: CVE-2018-7891

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 104120

SOURCES

db:CNVDid:CNVD-2018-10185
db:BIDid:104120
db:JVNDBid:JVNDB-2018-004979
db:CNNVDid:CNNVD-201805-041
db:NVDid:CVE-2018-7891

LAST UPDATE DATE

2024-11-23T22:26:24.859000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-10185date:2018-05-24T00:00:00
db:BIDid:104120date:2018-05-08T00:00:00
db:JVNDBid:JVNDB-2018-004979date:2019-12-26T00:00:00
db:CNNVDid:CNNVD-201805-041date:2018-05-07T00:00:00
db:NVDid:CVE-2018-7891date:2024-11-21T04:12:56.057

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-10185date:2018-05-24T00:00:00
db:BIDid:104120date:2018-05-08T00:00:00
db:JVNDBid:JVNDB-2018-004979date:2018-07-03T00:00:00
db:CNNVDid:CNNVD-201805-041date:2018-05-02T00:00:00
db:NVDid:CVE-2018-7891date:2018-04-30T15:29:00.287