Siemens released a hotfix to handle an authentication bypass vulnerability in its mobile server component of Siveillance Video 2022 R2 that could allow an unauthenticated remote attacker to access the application without a valid account, according to a report with Siemens ProductCERT.

Siveillance Video (formerly called Siveillance VMS) is IP video management software designed for deployments ranging from small and simple to large-scale and high-security. The Siveillance Video portfolio consists of four versions, Siveillance Video Core, Core Plus, Advanced, and Pro, addressing the specific needs of small and medium size solutions up to large complex deployments.

Siveillance Video Mobile Server V2022 R2, all version under v22.2a (80), suffer from the issue.

In the vulnerability, discovered by Milestone PSIRT, the mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow an unauthenticated remote attacker to access the application without a valid account.

CVE-2022-43400 is the case number assigned to the vulnerability, which has a CVSS 3.1 base score of 9.4.

Schneider Bold

To remediate the issue, users should update to V22.2a (80) or later version by applying the latest hotfix of the Mobile Server Installer (Vulnerability Hotfix).

In addition, Siemens identified the following specific workarounds and mitigations that customers can apply to reduce the risk: Enable the feature “Servers > Mobile Servers > Deny the built-in Administrators role access to the mobile servers” for all configured mobile servers.

As a general security measure Siemens recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.

ISSSource

Pin It on Pinterest

Share This