IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-825228: Potential Remote Code Execution in Siveillance Video Management Servers

CRITICAL
CVSS 9.1
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-3014 9.1 critical
CVE-2026-3014. Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.

// Remediations (3)

Patch: Update to V25.1 HotfixRev15 or later version
Update to V25.1 HotfixRev15 or later version
Patch: Update to V24.1 HotfixRev16 or later version
Update to V24.1 HotfixRev16 or later version
Patch: Update to V23.3 HotfixRev27 or later version
Update to V23.3 HotfixRev27 or later version

// References