VDB

GCVE-110-NCSC-2026-282

GCVE-110-NCSC-2026-282
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published August 11, 2026
Milestone released an updated version of XProtect and cumulative patches addressing a security vulnerability in the Management Server API that permitted users with edit permissions to execute arbitrary code within the Management Server Service context.

Weaknesses (CWE)

CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-125Out-of-bounds ReadCWE-787Out-of-bounds WriteCWE-416Use After FreeCWE-321Use of Hard-coded Cryptographic KeyCWE-759Use of a One-Way Hash without a SaltCWE-306Missing Authentication for Critical FunctionCWE-121Stack-based Buffer OverflowCWE-754Improper Check for Unusual or Exceptional ConditionsCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-732Incorrect Permission Assignment for Critical ResourceCWE-35Path Traversal: '.../...//'

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Siemensvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›