Siemens Siveillance Video Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: - Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) - Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) - Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 9.1 | Siemens | Siemens Siveillance Video | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Background - Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities - Countries/Areas Deployed: Worldwide - Company Headquarters Location: Germany Vulnerabilities CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. Affected Products Siemens Siveillance Video Siemens Siveillance Video V2023 R3 < V23.3.27, Siveillance Video V2024 R1 < V24.1.16, Siveillance Video V2025 < V25.1.15 known_affected Remediations Vendor fix Update to V23.3 HotfixRev27 or later version https://support.industry.siemens.com/cs/ww/en/view/109827783/ Vendor fix Update to V24.1 HotfixRev16 or later version https://support.industry.siemens.com/cs/ww/en/view/109976123/ Vendor fix Update to V25.1 HotfixRev15 or later version https://support.industry.siemens.com/cs/ww/en/view/109988670/ Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics | CVSS Version | Base Score | Base Severity | Vector String | |---|---|---|---| | 3.1 | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | Acknowledgments - Milestone PSIRT reported this vulnerability to Siemens General Recommendations As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order