criticalOther

Siemens Siveillance Video Management Server OS Command Injection (CVE-2026-3014)

First seen Aug 15, 2026 · Updated Aug 15, 2026 · CVSS 9.1

ICSOTvulnerabilityOS-command-injectionSiemensvideo-management-systemphysical-securityCVE-2026-3014privileged-user-exploit

Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.

Technical Analysis

CVE-2026-3014 is an Improper Neutralization of Special Elements used in an OS Command (CWE-78) vulnerability affecting Siveillance Video V2023 R3 (<23.3.27), V2024 R1 (<24.1.16), and V2025 (<25.1.15), scoring 9.1 (CVSS 3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). Exploitation requires an authenticated user with edit permissions on the Management Server, who can then inject OS commands executed with Management Server Service privileges, leading to full compromise of confidentiality, integrity, and availability with scope change to underlying host systems. This is a video management/physical security surveillance platform rather than an AI agent framework component, but if organizations integrate video feeds, metadata, or Management Server APIs into AI-driven monitoring, computer-vision agents, or automated incident-response pipelines, a compromised Management Server could feed poisoned data or serve as a pivot point to credentials/API keys used by connected agent systems, warranting inclusion in agent-impact risk assessments.

Affected Systems

Siemens Siveillance Video V2023 R3 versions prior to V23.3.27 (V23.3 HotfixRev27); Siveillance Video V2024 R1 versions prior to V24.1.16 (V24.1 HotfixRev16); Siveillance Video V2025 versions prior to V25.1.15 (V25.1 HotfixRev15). Deployed in Critical Manufacturing, Communications, and Commercial Facilities sectors worldwide.

Indicators of Compromise

  • No IOCs published; this is a vulnerability advisory without known active exploitation indicators.

Remediation Steps

  1. 1

    Update Siveillance Video V2023 R3

    Upgrade to V23.3 HotfixRev27 or later per Siemens support portal (109827783).

  2. 2

    Update Siveillance Video V2024 R1

    Upgrade to V24.1 HotfixRev16 or later per Siemens support portal (109976123).

  3. 3

    Update Siveillance Video V2025

    Upgrade to V25.1 HotfixRev15 or later per Siemens support portal (109988670).

  4. 4

    Restrict Management Server edit permissions

    Limit and audit accounts with edit permissions to the Management Server, as exploitation requires privileged access.

  5. 5

    Network segmentation

    Isolate control system and video management networks from business networks and the internet; use firewalls and VPNs with proper hardening for remote access.

  6. 6

    Monitor and report

    Monitor Management Server activity for anomalous command execution and report suspected malicious activity to CISA.

CVE / Advisory IDs

CVE-2026-3014

Industries Most Exposed

Critical ManufacturingCommunicationsCommercial FacilitiesPhysical Security/Surveillance

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.