Full Report
Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Remote Code Execution in Siemens Siveillance Video Management Servers
## CVE Details
- **CVE ID:** CVE-2026-3014
- **CVSS Score:** 9.1 (Critical) - CVSS v3.1 / 6.4 (Medium) - CVSS v4.0
- **CWE:** CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
## Affected Systems
- **Products:** Siveillance Video (formerly Siveillance VMS) - Core, Core Plus, Advanced, and Pro editions.
- **Versions:**
- Siveillance Video V2023 R3: All versions < V23.3 HotfixRev27
- Siveillance Video V2024 R1: All versions < V24.1 HotfixRev16
- Siveillance Video V2025: All versions < V25.1 HotfixRev15
- **Configurations:** Systems where the Management Server API is accessible to users with administrative "edit" permissions.
## Vulnerability Description
A vulnerability exists in the Management Server API of the Milestone XProtect engine used by Siemens Siveillance. Due to improper neutralization of special elements in OS commands (Command Injection), an authenticated user with edit permissions to the Management Server can execute arbitrary code. This execution occurs within the security context of the Management Server Service.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild (coordinated disclosure via Milestone PSIRT).
- **Complexity:** Low
- **Attack Vector:** Network
- **Privileges Required:** High (Requires users with edit permissions to the Management Server).
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- **Scope:** Changed (The vulnerability allows an attacker to impact components beyond the immediate security scope of the application).
## Remediation
### Patches
Siemens recommends updating affected products to the following versions or later:
- **Siveillance Video V2023 R3:** Update to V23.3 HotfixRev27
- **Siveillance Video V2024 R1:** Update to V24.1 HotfixRev16
- **Siveillance Video V2025:** Update to V25.1 HotfixRev15
### Workarounds
- **Network Segmentation:** Protect network access to the Management Server with appropriate security mechanisms (firewalls, VLANs).
- **Access Control:** Restrict administrative "edit" permissions to the Management Server to only trusted and essential personnel.
- **Environment Hardening:** Ensure the software is running within a protected IT environment following general security best practices.
## Detection
- **Indicators of Compromise:** Unusual OS-level commands or processes originating from the Management Server Service account.
- **Detection Methods:** Monitor Management Server API logs for anomalous input or unauthorized configuration changes. Audit account activities for users possessing high-level "edit" permissions.
## References
- **Siemens Advisory:** hxxps://cert-portal.siemens[.]com/productcert/html/ssa-825228.html
- **Milestone Security Advisory:** hxxps://support.milestonesys[.]com/article/CVE-2026-3014-potential-remote-code-execution-by-admin-user-on-Management-Server
- **Siemens ProductCERT:** hxxps://www.siemens[.]com/cert/advisories