CRITICAL · 9.8

CVE-2021-33044

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Vulnerability Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecurityIpc-Hum7Xxx Firmware< 2.820.0000000.5.r.210705
DahuasecurityIpc-Hum7Xxx-
DahuasecurityIpc-Hx3Xxx Firmware< 2.800.0000000.29.r.210630
DahuasecurityIpc-Hx3Xxx-
DahuasecurityIpc-Hx5Xxx Firmware< 2.820.0000000.18.r.210705
DahuasecurityIpc-Hx5Xxx-
DahuasecuritySd1A1 Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd1A1-
DahuasecuritySd22 Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd22-
DahuasecuritySd49 Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd49-
DahuasecuritySd50 Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd50-
DahuasecuritySd52C Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd52C-
DahuasecuritySd6Al Firmware< 2.812.0000007.0.r.210706
DahuasecuritySd6Al-
DahuasecurityTpc-Bf1241 Firmware< 2.630.0000000.6.r.210707
DahuasecurityTpc-Bf1241-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33044?

CVE-2021-33044 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

How severe is CVE-2021-33044?

CVE-2021-33044 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-33044?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Ipc-Hum7Xxx Firmware, Dahuasecurity Ipc-Hum7Xxx, Dahuasecurity Ipc-Hx3Xxx Firmware, Dahuasecurity Ipc-Hx3Xxx, Dahuasecurity Ipc-Hx5Xxx Firmware.