peter bassill · operator
$ cve CVE-2021-33045 JSON

CVE-2021-33045 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-09-11.

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.59% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVyes — remediate by 2024-09-11
Public exploitnone known
Published2021-09-15
Last modified2026-06-17

CISA KEV

NameDahua IP Camera Authentication Bypass Vulnerability
Added2024-08-21
Due2024-09-11
Vendor / productDahua / IP Camera Firmware
Ransomware usenone reported

Affected (36)

VendorProduct
dahuasecurityipc-hum7xxx
dahuasecurityipc-hum7xxx firmware
dahuasecurityipc-hx3xxx
dahuasecurityipc-hx3xxx firmware
dahuasecurityipc-hx5xxx
dahuasecurityipc-hx5xxx firmware
dahuasecuritynvr-1xxx
dahuasecuritynvr-1xxx firmware
dahuasecuritynvr-2xxx
dahuasecuritynvr-2xxx firmware
dahuasecuritynvr-4xxx
dahuasecuritynvr-4xxx firmware
dahuasecuritynvr-5xxx
dahuasecuritynvr-5xxx firmware
dahuasecuritynvr-6xx
dahuasecuritynvr-6xx firmware
dahuasecurityvth-542xh
dahuasecurityvth-542xh firmware
dahuasecurityvto-65xxx
dahuasecurityvto-65xxx firmware
dahuasecurityvto-75x95x
dahuasecurityvto-75x95x firmware
dahuasecurityxvr-4x04
dahuasecurityxvr-4x04 firmware
dahuasecurityxvr-4x08
dahuasecurityxvr-4x08 firmware
dahuasecurityxvr-5x04
dahuasecurityxvr-5x04 firmware
dahuasecurityxvr-5x08
dahuasecurityxvr-5x08 firmware
dahuasecurityxvr-5x16
dahuasecurityxvr-5x16 firmware
dahuasecurityxvr-7x16
dahuasecurityxvr-7x16 firmware
dahuasecurityxvr-7x32
dahuasecurityxvr-7x32 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD