CVE-2021-27197
PoC —CVSS 3.1
8.1 high
EPSS
<1%p54
Published
()
Modified
Description
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and " ") to overwrite arbitrary files.
- Vendors
- pelco
- Products
- digital sentry server
- Weakness
- CWE-346
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.