Siemens Siveillance Video Management Server OS Command Injection (CVE-2026-3014)
First seen Aug 15, 2026 · Updated Aug 15, 2026 · CVSS 9.1
Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.
Technical Analysis
CVE-2026-3014 is an Improper Neutralization of Special Elements used in an OS Command (CWE-78) vulnerability affecting Siveillance Video V2023 R3 (<23.3.27), V2024 R1 (<24.1.16), and V2025 (<25.1.15), scoring 9.1 (CVSS 3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). Exploitation requires an authenticated user with edit permissions on the Management Server, who can then inject OS commands executed with Management Server Service privileges, leading to full compromise of confidentiality, integrity, and availability with scope change to underlying host systems. This is a video management/physical security surveillance platform rather than an AI agent framework component, but if organizations integrate video feeds, metadata, or Management Server APIs into AI-driven monitoring, computer-vision agents, or automated incident-response pipelines, a compromised Management Server could feed poisoned data or serve as a pivot point to credentials/API keys used by connected agent systems, warranting inclusion in agent-impact risk assessments.
Affected Systems
Siemens Siveillance Video V2023 R3 versions prior to V23.3.27 (V23.3 HotfixRev27); Siveillance Video V2024 R1 versions prior to V24.1.16 (V24.1 HotfixRev16); Siveillance Video V2025 versions prior to V25.1.15 (V25.1 HotfixRev15). Deployed in Critical Manufacturing, Communications, and Commercial Facilities sectors worldwide.
Indicators of Compromise
- No IOCs published; this is a vulnerability advisory without known active exploitation indicators.
Remediation Steps
- 1
Update Siveillance Video V2023 R3
Upgrade to V23.3 HotfixRev27 or later per Siemens support portal (109827783).
- 2
Update Siveillance Video V2024 R1
Upgrade to V24.1 HotfixRev16 or later per Siemens support portal (109976123).
- 3
Update Siveillance Video V2025
Upgrade to V25.1 HotfixRev15 or later per Siemens support portal (109988670).
- 4
Restrict Management Server edit permissions
Limit and audit accounts with edit permissions to the Management Server, as exploitation requires privileged access.
- 5
Network segmentation
Isolate control system and video management networks from business networks and the internet; use firewalls and VPNs with proper hardening for remote access.
- 6
Monitor and report
Monitor Management Server activity for anomalous command execution and report suspected malicious activity to CISA.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.