8.1
CVSSv3

CVE-2021-27197

Published: 12/02/2021 Updated: 19/02/2021
CVSS v2 Base Score: 8.8 | Impact Score: 9.2 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 783
Vector: AV:N/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

DSUtility.dll in Pelco Digital Sentry Server prior to 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pelco digital sentry server