PatchSiren cyber security CVE debrief
CVE-2024-3506 Milestone Systems CVE debrief
A buffer overflow vulnerability exists in selected camera drivers within the Siemens Siveillance Video Device Pack (formerly XProtect Device Pack). An attacker with internal network access can potentially execute commands on the Recording Server under strict conditions. The vulnerability was disclosed on October 10, 2024, and last modified on May 6, 2025. CISA assigned this issue a CVSS 3.1 score of 6.7 (Medium severity). The attack requires adjacent network access, high attack complexity, no privileges, and user interaction. Siemens has released a vendor fix in version 13.2 or later.
- Vendor
- Milestone Systems
- Product
- Siveillance Video Device Pack
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-10-10
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-10-10
- Advisory updated
- 2025-05-06
Who should care
Organizations operating Siemens Siveillance Video surveillance systems with Device Pack versions prior to 13.2, particularly those in critical infrastructure, enterprise security, and industrial environments where physical security systems integrate with operational technology networks.
Technical summary
The vulnerability stems from a possible buffer overflow condition in selected camera drivers bundled with the XProtect Device Pack component of Siemens Siveillance Video. Successful exploitation requires an attacker to have access to the internal network where the Recording Server operates. The attack complexity is rated high, and user interaction is required. If exploited, the vulnerability could allow command execution on the Recording Server, with impacts to confidentiality and integrity rated high and availability impact rated low. The attack does not cross security boundaries (scope unchanged).
Defensive priority
medium
Recommended defensive actions
- Update Siveillance Video Device Pack to version 13.2 or later to address the buffer overflow vulnerability.
- When adding new cameras, configure scanning to target only IP addresses confirmed to be valid and trusted devices.
- Implement network segmentation to restrict internal network access to the Recording Server and camera infrastructure.
- Apply defense-in-depth strategies for industrial control systems as recommended by CISA.
- Monitor for anomalous network activity targeting camera driver interfaces on affected systems.
Evidence notes
CISA CSAF advisory ICSA-24-289-01 provides the primary disclosure. Siemens published security advisory SSA-438590 with remediation guidance. The CVSS vector (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L) confirms adjacent network attack vector with high complexity.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-3506 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-3506
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-3506 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-3506
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-289-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-438590.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-438590.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-289-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.