9.8

CVE-2021-33046

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DahuasecurityIpc-hx1xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityIpc-hx1xxx Version-
DahuasecurityIpc-hx2xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityIpc-hx2xxx Version-
DahuasecurityIpc-hx3xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityIpc-hx3xxx Version-
DahuasecurityIpc-hx5(4)(3)xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityIpc-hx5(4)(3)xxx Version-
DahuasecurityIpc-hx5xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityIpc-hx5xxx Version-
DahuasecuritySd1a1 Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd1a1 Version-
DahuasecuritySd22 Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd22 Version-
DahuasecuritySd49 Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd49 Version-
DahuasecuritySd50 Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd50 Version-
DahuasecuritySd52c Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd52c Version-
DahuasecuritySd6al Firmware Version >= 2017-7 <= 2021-7
   DahuasecuritySd6al Version-
DahuasecurityTpc-bf1241 Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-bf1241 Version-
DahuasecurityTpc-bf2221 Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-bf2221 Version-
DahuasecurityTpc-bf5x01 Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-bf5x01 Version-
DahuasecurityTpc-pt8x21x Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-pt8x21x Version-
DahuasecurityTpc-sd2221 Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-sd2221 Version-
DahuasecurityTpc-sd8x21 Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityTpc-sd8x21 Version-
DahuasecurityNvr1xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityNvr1xxx Version-
DahuasecurityNvr2xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityNvr2xxx Version-
DahuasecurityNvr4xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityNvr4xxx Version-
DahuasecurityNvr5xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityNvr5xxx Version-
DahuasecurityXvr4xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityXvr4xxx Version-
DahuasecurityXvr5xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityXvr5xxx Version-
DahuasecurityXvr7xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityXvr7xxx Version-
DahuasecurityHcvr7xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityHcvr7xxx Version-
DahuasecurityHcvr8xxx Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityHcvr8xxx Version-
DahuasecurityVtox20xf Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityVtox20xf Version-
DahuasecurityAsc2204c Firmware Version >= 2017-7 <= 2021-7
   DahuasecurityAsc2204c Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.652
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.