PatchSiren cyber security CVE debrief
CVE-2024-3506 Milestone Systems CVE debrief
A buffer overflow vulnerability exists in selected camera drivers within the Siemens Siveillance Video Device Pack (formerly XProtect Device Pack). An attacker with internal network access can potentially execute commands on the Recording Server under strict conditions. The vulnerability was disclosed on October 10, 2024, and last modified on May 6, 2025. CISA assigned this issue a CVSS 3.1 score of 6.7 (Medium severity). The attack requires adjacent network access, high attack complexity, no privileges, and user interaction. Siemens has released a vendor fix in version 13.2 or later.
- Vendor
- Milestone Systems
- Product
- Siveillance Video Device Pack
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-10-10
- Original CVE updated
- 2025-05-06
- Advisory published
- 2024-10-10
- Advisory updated
- 2025-05-06
Who should care
Organizations operating Siemens Siveillance Video surveillance systems with Device Pack versions prior to 13.2, particularly those in critical infrastructure, enterprise security, and industrial environments where physical security systems integrate with operational technology networks.
Technical summary
The vulnerability stems from a possible buffer overflow condition in selected camera drivers bundled with the XProtect Device Pack component of Siemens Siveillance Video. Successful exploitation requires an attacker to have access to the internal network where the Recording Server operates. The attack complexity is rated high, and user interaction is required. If exploited, the vulnerability could allow command execution on the Recording Server, with impacts to confidentiality and integrity rated high and availability impact rated low. The attack does not cross security boundaries (scope unchanged).
Defensive priority
medium
Recommended defensive actions
- Update Siveillance Video Device Pack to version 13.2 or later to address the buffer overflow vulnerability.
- When adding new cameras, configure scanning to target only IP addresses confirmed to be valid and trusted devices.
- Implement network segmentation to restrict internal network access to the Recording Server and camera infrastructure.
- Apply defense-in-depth strategies for industrial control systems as recommended by CISA.
- Monitor for anomalous network activity targeting camera driver interfaces on affected systems.
Evidence notes
CISA CSAF advisory ICSA-24-289-01 provides the primary disclosure. Siemens published security advisory SSA-438590 with remediation guidance. The CVSS vector (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L) confirms adjacent network attack vector with high complexity.
Official resources
-
CVE-2024-3506 CVE record
CVE.org
-
CVE-2024-3506 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-10-10