← Back

CVE-2026-33560

nvd nist
Published: Jun 26, 2026Modified: Jul 6, 2026

JSON object

Loading...
8.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ics-cert@hq.dhs.gov (Secondary)

Description

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

Affected (9)

3 products
Dmp 5000 Firmware
Dmp 8000 Firmware
Vfc Dmp 5000 Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Daktronics
Before 8.117.0.0
From 10.0.0.0 to 10.34.0.0
From 9.0.0.0 to 9.43.0.0
Running on/withPlatform Versions
Daktronics
Dmp 5000
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Daktronics
Before 8.117.0.0
From 10.0.0.0 to 10.34.0.0
From 9.0.0.0 to 9.43.0.0
Running on/withPlatform Versions
Daktronics
Dmp 8000
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Daktronics
Before 8.117.0.0
From 10.0.0.0 to 10.34.0.0
From 9.0.0.0 to 9.43.0.0
Running on/withPlatform Versions
Daktronics
Vfc Dmp 5000
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.