10

CVE-2021-33044

Warnung
Exploit
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityIpc-hum7xxx Firmware Version < 2.820.0000000.5.r.210705
   DahuasecurityIpc-hum7xxx Version-
DahuasecurityIpc-hx3xxx Firmware Version < 2.800.0000000.29.r.210630
   DahuasecurityIpc-hx3xxx Version-
DahuasecurityIpc-hx5xxx Firmware Version < 2.820.0000000.18.r.210705
   DahuasecurityIpc-hx5xxx Version-
DahuasecuritySd1a1 Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd1a1 Version-
DahuasecuritySd22 Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd22 Version-
DahuasecuritySd49 Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd49 Version-
DahuasecuritySd50 Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd50 Version-
DahuasecuritySd52c Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd52c Version-
DahuasecuritySd6al Firmware Version < 2.812.0000007.0.r.210706
   DahuasecuritySd6al Version-
DahuasecurityTpc-bf1241 Firmware Version < 2.630.0000000.6.r.210707
   DahuasecurityTpc-bf1241 Version-
DahuasecurityTpc-bf2221 Firmware Version < 2.630.0000000.10.r.210707
   DahuasecurityTpc-bf2221 Version-
DahuasecurityTpc-bf5x01 Firmware Version < 2.630.0000000.12.r.210707
   DahuasecurityTpc-bf5x01 Version-
DahuasecurityTpc-pt8x21b Firmware Version < 2.630.0000000.10.r.210701
   DahuasecurityTpc-pt8x21b Version-
DahuasecurityTpc-sd2221 Firmware Version <= 2.630.0000000.7.r.210707
   DahuasecurityTpc-sd2221 Version-
DahuasecurityTpc-sd8x21 Firmware Version < 2.630.0000000.9.r.210706
   DahuasecurityTpc-sd8x21 Version-
DahuasecurityVto-65xxx Firmware Version < 4.300.0000004.0.r.210715
   DahuasecurityVto-65xxx Version-
DahuasecurityVto-75x95x Firmware Version < 4.300.0000003.0.r.210714
   DahuasecurityVto-75x95x Version-
DahuasecurityVth-542xh Firmware Version < 4.500.0000002.0.r.210715
   DahuasecurityVth-542xh Version-
DahuasecurityTpc-bf5x21 Firmware Version < 2.630.0000000.8.r.210630
   DahuasecurityTpc-bf5x21 Version-

21.08.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Dahua IP Camera Authentication Bypass Vulnerability

Schwachstelle

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.27% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.