CVE-2021-27197: High severity pelco digital sentry vulnerability
DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the application or from a malicious user. The vulnerability is triggered when a remote attacker crafts an HTML page (e.g., with "OBJECT classid=" and "<SCRIPT language='vbscript'>") to overwrite arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27197?
CVE-2021-27197 is an arbitrary file write vulnerability in DSUtility.dll in Pelco Digital Sentry Server before 7.19.67.
How does CVE-2021-27197 work?
CVE-2021-27197 is triggered when a remote attacker crafts an HTML page that exploits the vulnerability in DSUtility.dll's AppendToTextFile method.
What is the severity of CVE-2021-27197?
CVE-2021-27197 has a severity rating of 8.1 out of 10, indicating a high severity.
Which software versions are affected by CVE-2021-27197?
The arbitrary file write vulnerability (CVE-2021-27197) affects Pelco Digital Sentry Server versions up to 7.19.67.
How can I fix CVE-2021-27197?
To fix CVE-2021-27197, it is recommended to update Pelco Digital Sentry Server to version 7.19.67 or newer.