Improper access control in Digital Sentry - CVE-2021-27197
Published: February 16, 2021
Digital Sentry
Pelco
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the "AppendToTextFile" method in DSUtility.dll. A remote attacker can trick a victim to open a specially crafted webpage and write arbitrary files on the system.