CVE-2021-33045
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Dahua IP Camera Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-287
מוצרים מושפעים
dahuasecurity: ipc-hum7xxx firmware; dahuasecurity: ipc-hum7xxx; dahuasecurity: ipc-hx3xxx firmware; dahuasecurity: ipc-hx3xxx; dahuasecurity: ipc-hx5xxx firmware; dahuasecurity: ipc-hx5xxx; dahuasecurity: nvr-1xxx firmware; dahuasecurity: nvr-1xxx; dahuasecurity: nvr-2xxx firmware; dahuasecurity: nvr-2xxx; dahuasecurity: nvr-4xxx firmware; dahuasecurity: nvr-4xxx; dahuasecurity: nvr-5xxx firmware; dahuasecurity: nvr-5xxx; dahuasecurity: nvr-6xx firmware
קישורים
- https://www.dahuasecurity.com/support/cybersecurity/details/957 Vendor Advisory
- https://www.dahuasecurity.com/support/cybersecurity/details/957 Vendor Advisory
- http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/13 ExploitMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html ExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2021/Oct/13 ExploitMailing ListThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource