peter bassill · operator
$ cve CVE-2021-33044 JSON

CVE-2021-33044 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-09-11.

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.99% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2024-09-11
Public exploitnone known
Published2021-09-15
Last modified2026-06-17

CISA KEV

NameDahua IP Camera Authentication Bypass Vulnerability
Added2024-08-21
Due2024-09-11
Vendor / productDahua / IP Camera Firmware
Ransomware usenone reported

Affected (38)

VendorProduct
dahuasecurityipc-hum7xxx
dahuasecurityipc-hum7xxx firmware
dahuasecurityipc-hx3xxx
dahuasecurityipc-hx3xxx firmware
dahuasecurityipc-hx5xxx
dahuasecurityipc-hx5xxx firmware
dahuasecuritysd1a1
dahuasecuritysd1a1 firmware
dahuasecuritysd22
dahuasecuritysd22 firmware
dahuasecuritysd49
dahuasecuritysd49 firmware
dahuasecuritysd50
dahuasecuritysd50 firmware
dahuasecuritysd52c
dahuasecuritysd52c firmware
dahuasecuritysd6al
dahuasecuritysd6al firmware
dahuasecuritytpc-bf1241
dahuasecuritytpc-bf1241 firmware
dahuasecuritytpc-bf2221
dahuasecuritytpc-bf2221 firmware
dahuasecuritytpc-bf5x01
dahuasecuritytpc-bf5x01 firmware
dahuasecuritytpc-bf5x21
dahuasecuritytpc-bf5x21 firmware
dahuasecuritytpc-pt8x21b
dahuasecuritytpc-pt8x21b firmware
dahuasecuritytpc-sd2221
dahuasecuritytpc-sd2221 firmware
dahuasecuritytpc-sd8x21
dahuasecuritytpc-sd8x21 firmware
dahuasecurityvth-542xh
dahuasecurityvth-542xh firmware
dahuasecurityvto-65xxx
dahuasecurityvto-65xxx firmware
dahuasecurityvto-75x95x
dahuasecurityvto-75x95x firmware

References

→ the Explorer  ·  watch your stack  ·  NVD