CVE-2025-1688

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 15, 2025
CWE ID 311

Summary

CVE-2025-1688 is a security vulnerability affecting Milestone XProtect installers. This issue resets the system configuration password after upgrading from older versions using specific installers. The system configuration password is an optional security feature on the Management Server. To mitigate this vulnerability, Milestone Systems advises updating the system configuration password using the GUI. Systems upgraded with the 2024 R1 or 2024 R2 release installers are at risk, while those upgraded from 2023 R3 or older with version 2025 R1 and above remain unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • XProtect

Affected Vendors

  • Milestone Systems