CRITICAL · 9.8

CVE-2021-33045

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Vulnerability Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DahuasecurityIpc-Hum7Xxx Firmware< 2.820.0000000.5.r.210705
DahuasecurityIpc-Hum7Xxx-
DahuasecurityIpc-Hx3Xxx Firmware< 2.800.0000000.29.r.210630
DahuasecurityIpc-Hx3Xxx-
DahuasecurityIpc-Hx5Xxx Firmware< 2.820.0000000.5.r.210705
DahuasecurityIpc-Hx5Xxx-
DahuasecurityNvr-1Xxx Firmware< 4.001.0000005.1.r.210709
DahuasecurityNvr-1Xxx-
DahuasecurityNvr-2Xxx Firmware< 4.001.0000000.1.r.210710
DahuasecurityNvr-2Xxx-
DahuasecurityNvr-4Xxx Firmware< 4.001.0000005.1.r.210713
DahuasecurityNvr-4Xxx-
DahuasecurityNvr-5Xxx Firmware< 4.001.0000000.0.r.210710
DahuasecurityNvr-5Xxx-
DahuasecurityNvr-6Xx Firmware< 4.001.0000001.1.r.210716
DahuasecurityNvr-6Xx-
DahuasecurityVth-542Xh Firmware< 4.500.0000002.0.r.210715
DahuasecurityVth-542Xh-
DahuasecurityVto-65Xxx Firmware< 4.300.0000004.0.r.210715
DahuasecurityVto-65Xxx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33045?

CVE-2021-33045 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

How severe is CVE-2021-33045?

CVE-2021-33045 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-33045?

Check the references section above for vendor advisories and patch information. Affected products include: Dahuasecurity Ipc-Hum7Xxx Firmware, Dahuasecurity Ipc-Hum7Xxx, Dahuasecurity Ipc-Hx3Xxx Firmware, Dahuasecurity Ipc-Hx3Xxx, Dahuasecurity Ipc-Hx5Xxx Firmware.