CVE-2024-12569: Milestone Systems Xprotect Vms
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.
Affected products
- Milestone Systems Xprotect Vms: before 13.5a (fixed in 13.5a)
Published 2024-12-19. Last modified 2026-06-17.