10

CVE-2021-33045

Warnung
Exploit
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityIpc-hum7xxx Firmware Version < 2.820.0000000.5.r.210705
   DahuasecurityIpc-hum7xxx Version-
DahuasecurityIpc-hx3xxx Firmware Version < 2.800.0000000.29.r.210630
   DahuasecurityIpc-hx3xxx Version-
DahuasecurityIpc-hx5xxx Firmware Version < 2.820.0000000.5.r.210705
   DahuasecurityIpc-hx5xxx Version-
DahuasecurityNvr-1xxx Firmware Version < 4.001.0000005.1.r.210709
   DahuasecurityNvr-1xxx Version-
DahuasecurityNvr-2xxx Firmware Version < 4.001.0000000.1.r.210710
   DahuasecurityNvr-2xxx Version-
DahuasecurityNvr-4xxx Firmware Version < 4.001.0000005.1.r.210713
   DahuasecurityNvr-4xxx Version-
DahuasecurityNvr-5xxx Firmware Version < 4.001.0000000.0.r.210710
   DahuasecurityNvr-5xxx Version-
DahuasecurityNvr-6xx Firmware Version < 4.001.0000001.1.r.210716
   DahuasecurityNvr-6xx Version-
DahuasecurityVth-542xh Firmware Version < 4.500.0000002.0.r.210715
   DahuasecurityVth-542xh Version-
DahuasecurityVto-65xxx Firmware Version < 4.300.0000004.0.r.210715
   DahuasecurityVto-65xxx Version-
DahuasecurityVto-75x95x Firmware Version < 4.300.0000003.0.r.210714
   DahuasecurityVto-75x95x Version-
DahuasecurityXvr-4x04 Firmware Version-
   DahuasecurityXvr-4x04 Version-
DahuasecurityXvr-4x08 Firmware Version < 4.001.0000001.1.r.210709
   DahuasecurityXvr-4x08 Version-
DahuasecurityXvr-4x04 Firmware Version < 4.001.0000001.1.r.210709
   DahuasecurityXvr-4x04 Version-
DahuasecurityXvr-5x04 Firmware Version < 4.001.0000003.1.r.210710
   DahuasecurityXvr-5x04 Version-
DahuasecurityXvr-5x08 Firmware Version < 4.001.0000003.1.r.210710
   DahuasecurityXvr-5x08 Version-
DahuasecurityXvr-5x16 Firmware Version < 4.001.0000003.1.r.210710
   DahuasecurityXvr-5x16 Version-
DahuasecurityXvr-7x16 Firmware Version < 4.001.0000003.1.r.210710
   DahuasecurityXvr-7x16 Version-
DahuasecurityXvr-7x32 Firmware Version < 4.001.0000003.1.r.210710
   DahuasecurityXvr-7x32 Version-

21.08.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Dahua IP Camera Authentication Bypass Vulnerability

Schwachstelle

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.17% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.