CVE-2021-27184: XEE
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the ControlPointCacheShare.xml file (in a %APPDATA%\Pelco directory) when DSControlPoint.exe is executed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27184?
CVE-2021-27184 refers to an XML External Entity vulnerability in Pelco Digital Sentry Server 7.18.72.11464.
How does CVE-2021-27184 affect Pelco Digital Sentry Server?
CVE-2021-27184 allows for the disclosure and retrieval of arbitrary data on the affected server via an out-of-band attack.
What is the severity level of CVE-2021-27184?
CVE-2021-27184 has a severity level of 7.5 (high).
How can I fix the XML External Entity vulnerability in Pelco Digital Sentry Server?
To fix the vulnerability, update Pelco Digital Sentry Server to a version that is not affected by CVE-2021-27184.
Where can I find more information about Pelco Digital Sentry Server releases and revisions?
You can find more information about Pelco Digital Sentry Server releases and revisions on the Pelco support website.