vuln-advisoryregulatorNewsThe Broadside2 min read

Siemens Siveillance Video Servers Face CVSS 9.1 OS Command Injection

The servers watching your facility are now the ones that need watching, remotely exploitable, and patched only if someone knows they're there.


TL;DR

CISA published an advisory Tuesday for CVE-2026-3014, a CVSS 9.1 OS command injection flaw in Siemens Siveillance Video Management Servers. Authenticated users with edit permissions can execute arbitrary code on the Management Server; it's network-accessible and low complexity. Affected versions are V2023 R3 prior to V23.3.27, V2024 R1 prior to V24.1.16, V2025 prior to V25.1.15. The product runs in critical manufacturing, communications, and commercial facilities worldwide. Surveillance servers often fall outside routine vulnerability scanning because physical security teams own them, not IT. That inventory gap is where the risk lives.

CVE-2026-3014 sits in the Management Server API, the component that orchestrates cameras and recording servers across a Siveillance deployment. The flaw is a classic OS command injection (CWE-78): the API doesn't adequately sanitize special elements before passing them to the operating system. An attacker with edit permissions on the Management Server can reach across the network and execute arbitrary code in the context of the Management Server service. No user interaction required. The CVSS vector spells out the rest. It's network-accessible with low attack complexity, and the scope change means a compromised Management Server becomes a pivot point to other systems. A 9.1 isn't theoretical.

Siveillance Video is Siemens' rebadge of Milestone XProtect, one of the most widely deployed video management platforms globally. It sits in critical manufacturing and commercial facilities worldwide. And it's frequently invisible to the vulnerability management program. Physical security teams procure and maintain these systems. They don't report into the CISO. The servers don't show up in the Qualys or Tenable scans because nobody added them to the scope. This isn't a new problem for Siveillance specifically. CISA has published advisories for this product family at least five times since 2022, including a CVSS 9.9 deserialization flaw in 2023 and a CVSS 9.4 authentication bypass in 2022. Each time, the remediation assumes someone knows the box exists.

Patch. Siemens has released fixes for all three affected branches. V23.3 goes to HotfixRev27 or later. V24.1 goes to HotfixRev16 or later. V25.1 goes to HotfixRev15 or later. The advisory is a verbatim CISA republication of Siemens' CSAF advisory. CISA hasn't issued a binding operational directive for federal civilian agencies, and it's unclear whether Siveillance Video is deployed in that segment. Defense contractors and municipalities running the product are on their own clock. The first step isn't patching; it's confirming whether you're running Siveillance Video at all. If you don't know, ask physical security.


Published ·Deep Fathom