VDB
CVE-2025-0836
CVE-2025-0836
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.
EPSS 0.21% · 10.5th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
0.21%
10.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Milestone Systems | XProtect VMS | 23.3, 24.1, 24.2 |
Timeline
- Dec 16, 2025 EPSS Score
- Dec 16, 2025 CVE Published
- Dec 20, 2025 EPSS Score
- Dec 25, 2025 EPSS Score
- Dec 29, 2025 EPSS Score
- Jan 2, 2026 EPSS Score
- Jan 6, 2026 EPSS Score
- Jan 11, 2026 EPSS Score
- Jan 15, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
References
- https://supportcommunity.milestonesys.com/s/article/CVE-2025-0836-XProtect-MIP-API-broken-access-control?language=en_US vendor-advisory
- https://supportcommunity.milestonesys.com/s/article/XProtect-VMS-cumulative-patches-complete-list?language=en_US patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-0836 advisory
- https://doc.milestonesys.com/en-US/bundle/sec1504_latest/page/Milestone_Security_Advisory.html url