CVE-2021-27197

DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pelco:digital_sentry_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://github.com/vitorespf/Advisories/blob/master/Pelco_Digital_Sentry_Server_AFW.txt - Exploit, Third Party Advisory () https://github.com/vitorespf/Advisories/blob/master/Pelco_Digital_Sentry_Server_AFW.txt - Exploit, Third Party Advisory
References () https://support.pelco.com/s/article/What-is-the-Digital-Sentry-software-release-revision-history - Release Notes, Vendor Advisory () https://support.pelco.com/s/article/What-is-the-Digital-Sentry-software-release-revision-history - Release Notes, Vendor Advisory

Information

Published : 2021-02-12 16:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27197

Mitre link : CVE-2021-27197

CVE.ORG link : CVE-2021-27197


JSON object : View

Products Affected

pelco

  • digital_sentry_server
CWE
CWE-346

Origin Validation Error