Siemens Patches Critical Command Injection in Siveillance Video
CVE-2026-3014 scores 9.1 despite requiring authentication, the scope change means compromised edit permissions cascade to full system compromise; hotfixes now cover three version branches.
TL;DR
CISA republished a Siemens advisory Tuesday for CVE-2026-3014, an OS command injection vulnerability in Siveillance Video management servers with a CVSS 3.1 score of 9.1. Affected versions: V2023 R3 before V23.3.27, V2024 R1 before V24.1.16, and V2025 before V25.1.15. The flaw requires authenticated access with edit permissions (it isn't unauthenticated internet-facing RCE) but the scope change and full CIA impact keep it critical. Siemens released hotfix revisions for all three branches, with no workaround offered.
CISA published an advisory Tuesday for CVE-2026-3014, a critical OS command injection vulnerability in Siemens Siveillance Video management servers. The flaw carries a CVSS 3.1 base score of 9.1, driven by a scope change (S:C) and high impact across confidentiality, integrity, and availability. The attack vector is network-based with low complexity, but the privileges required are high: an attacker needs authenticated access with edit permissions on the management server. That constraint makes mass exploitation less likely than an unauthenticated RCE, but the scope change (where the compromised management server service becomes a launch point into the broader environment) is what keeps the score in critical territory.
The advisory covers three version branches. Siveillance Video V2023 R3 needs upgrading to V23.3 HotfixRev27 or later. V2024 R1 requires V24.1 HotfixRev16 or later. V2025 requires V25.1 HotfixRev15 or later. Siemens published separate support bulletins for each branch. There's no mention of mitigations short of patching, no workaround, no configuration change that neutralizes the vector. The general recommendation to "protect network access with appropriate mechanisms" is standard boilerplate and doesn't reduce the urgency for anyone running these versions in critical manufacturing, communications, or commercial facilities environments.
One detail worth flagging for teams managing their patch inventory: the advisory body inadvertently confirms that Siveillance Video is a rebranded version of Milestone XProtect. The CSAF text states plainly that "Milestone has released a new version of XProtect (and several cumulative patch updates) which fix security vulnerability in Management Server API." Milestone PSIRT reported the vulnerability to Siemens. Organizations running Siveillance Video should verify whether any separately managed Milestone XProtect deployments are also affected and patched. Siemens's advisory doesn't address that question, but the overlap is right there in the text CISA republished verbatim.
Published ·Updated ·Deep Fathom