CVE-2018-7891 describes a critical deserialization vulnerability within Milestone XProtect Video Management Software versions 2016 R1 through 2018 R1, affecting both Milestone and Siemens branded products. This flaw allows unauthenticated remote attackers to achieve arbitrary remote code execution due to vulnerable .NET Remoting endpoints. With a CVSS score of 8.1 (High), the attack complexity is high, but successful exploitation grants full confidentiality, integrity, and availability impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.a, <= 12.1aCPE matchmatch criteria | cpe:2.3:a:milestonesys:xprotect:*:*:*:*:corporate:*:*:* | ||
>= 10.0.a, <= 12.1aCPE matchmatch criteria | cpe:2.3:a:milestonesys:xprotect:*:*:*:*:essential\+:*:*:* | ||
>= 10.0.a, <= 12.1aCPE matchmatch criteria | cpe:2.3:a:milestonesys:xprotect:*:*:*:*:expert:*:*:* | ||
>= 10.0.a, <= 12.1aCPE matchmatch criteria | cpe:2.3:a:milestonesys:xprotect:*:*:*:*:express\+:*:*:* | ||
>= 10.0.a, <= 12.1aCPE matchmatch criteria | cpe:2.3:a:milestonesys:xprotect:*:*:*:*:professional\+:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.