Vulnerability Description
The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potentially execute arbitrary attacker-supplied code. The victim would have to visit a malicious webpage using Internet Explorer where the exploit could be triggered.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pelco | Digital Sentry Server | 7.18.72.11464 |
Related Weaknesses (CWE)
References
- https://github.com/vitorespf/Advisories/blob/master/Pelco_Digital_Sentry_Server-ExploitThird Party Advisory
- https://support.pelco.com/s/article/What-is-the-Digital-Sentry-software-release-Vendor Advisory
- https://github.com/vitorespf/Advisories/blob/master/Pelco_Digital_Sentry_Server-ExploitThird Party Advisory
- https://support.pelco.com/s/article/What-is-the-Digital-Sentry-software-release-Vendor Advisory
FAQ
What is CVE-2021-27232?
CVE-2021-27232 is a vulnerability with a CVSS score of 8.8 (HIGH). The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potential...
How severe is CVE-2021-27232?
CVE-2021-27232 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27232?
Check the references section above for vendor advisories and patch information. Affected products include: Pelco Digital Sentry Server.