Buffer overflow in Digital Sentry - CVE-2021-27232

 

Buffer overflow in Digital Sentry - CVE-2021-27232

Published: February 18, 2021


Vulnerability identifier: #VU50802
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2021-27232
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Digital Sentry
Software vendor:
Pelco

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the RTSPLive555.dll ActiveX control in SetCameraConnectionParameter. A remote attacker can trick a victim to visit a malicious website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links