When the NVMS Configuration API is used to modify security settings, it fails to perform the necessary security checks. There are hotfixes available for versions 2016-R3 through 2017-R2.
Missing authorization validation when changing device properties (Version 2016-R3 and 2017-R2)
Incorrect authorization validation when changing role security (Version 2017-R2)
We have identified three related vulnerabilities in the NVMS Configuration API that can cause an elevation of privileges and affect the Management Server's security if exploited in Network Video Management System Enterprise Edition.
Apply the hotfix in the following sequence -- first to Recording Server(s), next to Management Server, finally to Management Client(s). Do not forget to apply the Recording Server patch also to the Failover Recording Server (if you are using a Failover Server).
Stop the Recording Server service, and exit the Recording Server Manager in the task tray
Go to C:\Program Files\Sony\- Network VMS Recording Server\
Create a backup of the following files:
"VideoOS.IO.Drivers.dll"
"VideoOS.Recorder.Service.exe"
"VideoOS.Recorder.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Replace the following files with the hotfixed ones:
"VideoOS.IO.Drivers.dll"
"VideoOS.Recorder.Service.exe"
"VideoOS.Recorder.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Go to C:\Program Files\Sony\- Network VMS Recording Server\Drivers\
Create a backup of the file "VideoOS.IO.Drivers.Interop.dll"
Replace the file "VideoOS.IO.Drivers.Interop.dll" with the hotfixed one
Start the Recording Server service, and start the Recording Server Manager in the task tray
Stop the Management Server service, and exit the Management Server Manager in the task tray
Go to C:\Program Files\Sony\- Network VMS Management Server\
Create a backup of the following files:
"VideoOS.Server.dll"
"VideoOS.Common.Integration.dll"
"VideoOS.Management.Server.dll"
"GenuineChannels.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Server.dll"
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Go to C:\Program Files\Sony\- Network VMS Management Server\IIS\ManagementServer\bin\
Create a backup of the following files:
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
Start the Management Server service, and start the Management Server Manager in the task tray
Close the Management Client
Go to C:\Program Files\Sony\- Network VMS Management Client\
Create a backup of the following files:
"VideoOS.Common.Integration.dll"
"VideoOS.Administration.Controls.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Common.Integration.dll"
"VideoOS.Administration.Controls.dll"
Start the Management Client
Apply the hotfix in the following sequence -- first to Recording Server(s), next to Management Server, finally to Management Client(s). Do not forget to apply the Recording Server patch also to the Failover Recording Server (if you are using a Failover Server).
Stop the Recording Server service, and exit the Recording Server Manager in the task tray
Go to C:\Program Files\Sony\- Network VMS Recording Server\
Create a backup of the following files:
"VideoOS.Recorder.Service.exe"
"VideoOS.Recorder.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Recorder.Service.exe"
"VideoOS.Recorder.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Start the Recording Server service, and start the Recording Server Manager in the task tray
Stop the Management Server service, and exit the Management Server Manager in the task tray
Go to C:\Program Files\Sony\- Network VMS Management Server\
Create a backup of the following files:
"VideoOS.Server.dll"
"VideoOS.Common.Integration.dll"
"VideoOS.Management.Server.dll"
"GenuineChannels.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Server.dll"
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
"GenuineChannels.dll"
Go to C:\Program Files\Sony\- Network VMS Management Server\IIS\ManagementServer\bin\
Create a backup of the following files:
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
Replace the following files with the hotfixed ones:
"VideoOS.Management.Server.dll"
"VideoOS.Common.Integration.dll"
Start the Management Server service, and start the Management Server Manager in the task tray
Close the Management Client
Go to C:\Program Files\Sony\- Network VMS Management Client\
Create a backup of the file "VideoOS.Common.Integration.dll"
Replace the file "VideoOS.Common.Integration.dll" with the hotfixed one
Start the Management Client
For the versions mentioned above, please use the hotfixes.
The hotfix download link is not published. Contact your local dealer for more support.