CVE-2021-33044
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Dahua IP Camera Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-287
מוצרים מושפעים
dahuasecurity: ipc-hum7xxx firmware; dahuasecurity: ipc-hum7xxx; dahuasecurity: ipc-hx3xxx firmware; dahuasecurity: ipc-hx3xxx; dahuasecurity: ipc-hx5xxx firmware; dahuasecurity: ipc-hx5xxx; dahuasecurity: sd1a1 firmware; dahuasecurity: sd1a1; dahuasecurity: sd22 firmware; dahuasecurity: sd22; dahuasecurity: sd49 firmware; dahuasecurity: sd49; dahuasecurity: sd50 firmware; dahuasecurity: sd50; dahuasecurity: sd52c firmware
קישורים
- https://www.dahuasecurity.com/support/cybersecurity/details/957 Vendor Advisory
- https://www.dahuasecurity.com/support/cybersecurity/details/957 Vendor Advisory
- http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/13 ExploitMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/13 ExploitMailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource