Pelco develops video surveillance and security management platforms, with vulnerabilities concentrated in products such as Digital Sentry Server and VideoXpert OpsCenter. The durable signal centers on application and data-handling issues including XML external entity references, origin validation errors, out-of-bounds writes, and uncontrolled search path elements, reflecting the complexity of networked video management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pelco over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27197HIGH DSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't check if it's being called from the appli | Feb 12, 2021 | 8.1 | 24 | NO | NO |
CVE-2021-27184HIGH Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting in disclosure and retrieval of | Feb 11, 2021 | 7.5 | 23 | NO | NO |
CVE-2018-7840HIGH A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorre | May 22, 2019 | 7.8 | 23 | NO | NO |
CVE-2021-27232HIGH The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote a | Feb 16, 2021 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pelco.
Media articles that mention a CVE ID that affects a product developed by Pelco — matched by CVE ID, not by vendor name.