ZeroHour

CVE-2021-27197

PoC
CVSS 3.1
8.1 high
EPSS
<1%p54
Published
()
Modified
Description

DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and " ") to overwrite arbitrary files.

Vendors
pelco
Products
digital sentry server
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.