Executive brief
Nx Witness VMS is a video management system used to monitor and manage surveillance cameras and video streams across networks. A cross-site scripting vulnerability in its web administration interface allows an attacker on the same network to inject malicious scripts that execute in an administrator's browser, enabling theft of the administrator's session credentials and complete takeover of the system.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the "Merge with Another Site" dialog of the Nx Witness VMS web administration interface. An attacker who controls an Nx server on the same network segment can set that server's site name to a malicious JavaScript payload. When an authenticated administrator opens the site selection list in the "Merge with Another Site" dialog, the payload executes in the administrator's browser context, allowing the attacker to steal the administrator's session token and achieve account takeover. Attack requires network adjacency (same network segment) and an authenticated administrator to trigger the vulnerable UI action. The vulnerability was patched in version 6.1.3.
Affected products
- Network Optix Nx Witness VMS before 6.1.3
Timeline
- 2026-08-24: disclosed