Vulnerability CVE-2021-27184


Published: 2021-02-11

Description:
Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the ControlPointCacheShare.xml file (in a %APPDATA%\Pelco directory) when DSControlPoint.exe is executed.

Type:

CWE-611

(Information Exposure Through XML External Entity Reference)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Pelco -> Digital sentry server 

 References:
https://github.com/vitorespf/Advisories/blob/master/Pelco_Digital_Sentry_Server.txt
https://support.pelco.com/s/article/What-is-the-Digital-Sentry-software-release-revision-history

Copyright 2024, cxsecurity.com

 

Back to Top