VDB
CVE-2025-0836
CVE-2025-0836
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.
EPSS 0.05% · 15.5th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
0.05%
15.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Milestone Systems | XProtect VMS | 23.3, 24.1, 24.2 |
Exploit Intelligence
Timeline
- Jan 29, 2025 CVE ID Reserved
- Dec 16, 2025 EPSS Score
- Dec 16, 2025 CVE Published
- Dec 16, 2025 CVE Updated
- Dec 20, 2025 EPSS Score
- Dec 24, 2025 EPSS Score
- Dec 28, 2025 EPSS Score
- Jan 1, 2026 EPSS Score
- Jan 5, 2026 EPSS Score
- Jan 9, 2026 EPSS Score
- Jan 13, 2026 EPSS Score
- Jan 17, 2026 EPSS Score
References
- https://supportcommunity.milestonesys.com/s/article/CVE-2025-0836-XProtect-MIP-API-broken-access-control?language=en_US vendor-advisory
- https://supportcommunity.milestonesys.com/s/article/XProtect-VMS-cumulative-patches-complete-list?language=en_US patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-0836 advisory
- https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/Milestone_Security_Advisory.html url