PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-3506 Milestone Systems CVE debrief

A buffer overflow vulnerability exists in selected camera drivers within the Siemens Siveillance Video Device Pack (formerly XProtect Device Pack). An attacker with internal network access can potentially execute commands on the Recording Server under strict conditions. The vulnerability was disclosed on October 10, 2024, and last modified on May 6, 2025. CISA assigned this issue a CVSS 3.1 score of 6.7 (Medium severity). The attack requires adjacent network access, high attack complexity, no privileges, and user interaction. Siemens has released a vendor fix in version 13.2 or later.

Vendor
Milestone Systems
Product
Siveillance Video Device Pack
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-10-10
Original CVE updated
2025-05-06
Advisory published
2024-10-10
Advisory updated
2025-05-06

Who should care

Organizations operating Siemens Siveillance Video surveillance systems with Device Pack versions prior to 13.2, particularly those in critical infrastructure, enterprise security, and industrial environments where physical security systems integrate with operational technology networks.

Technical summary

The vulnerability stems from a possible buffer overflow condition in selected camera drivers bundled with the XProtect Device Pack component of Siemens Siveillance Video. Successful exploitation requires an attacker to have access to the internal network where the Recording Server operates. The attack complexity is rated high, and user interaction is required. If exploited, the vulnerability could allow command execution on the Recording Server, with impacts to confidentiality and integrity rated high and availability impact rated low. The attack does not cross security boundaries (scope unchanged).

Defensive priority

medium

Recommended defensive actions

  • Update Siveillance Video Device Pack to version 13.2 or later to address the buffer overflow vulnerability.
  • When adding new cameras, configure scanning to target only IP addresses confirmed to be valid and trusted devices.
  • Implement network segmentation to restrict internal network access to the Recording Server and camera infrastructure.
  • Apply defense-in-depth strategies for industrial control systems as recommended by CISA.
  • Monitor for anomalous network activity targeting camera driver interfaces on affected systems.

Evidence notes

CISA CSAF advisory ICSA-24-289-01 provides the primary disclosure. Siemens published security advisory SSA-438590 with remediation guidance. The CVSS vector (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L) confirms adjacent network attack vector with high complexity.

Official resources

2024-10-10