CVE-2021-33045

CRITICALCVSS 9.8/10Actively ExploitedEPSS 99.56%

Last modified

CVE-2021-33045 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.56% chance of exploitation in the next 30 days.

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.56%

99.9th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
DahuasecurityIpc-Hum7xxx Firmware< 2.820.0000000.5.r.210705
DahuasecurityIpc-Hx3xxx Firmware< 2.800.0000000.29.r.210630
DahuasecurityIpc-Hx5xxx Firmware< 2.820.0000000.5.r.210705
DahuasecurityNvr-1xxx Firmware< 4.001.0000005.1.r.210709
DahuasecurityNvr-2xxx Firmware< 4.001.0000000.1.r.210710
DahuasecurityNvr-4xxx Firmware< 4.001.0000005.1.r.210713
DahuasecurityNvr-5xxx Firmware< 4.001.0000000.0.r.210710
DahuasecurityNvr-6xx Firmware< 4.001.0000001.1.r.210716
DahuasecurityVth-542xh Firmware< 4.500.0000002.0.r.210715
DahuasecurityVto-65xxx Firmware< 4.300.0000004.0.r.210715
DahuasecurityVto-75x95x Firmware< 4.300.0000003.0.r.210714
DahuasecurityXvr-4x04 FirmwareAll versions
DahuasecurityXvr-4x08 Firmware< 4.001.0000001.1.r.210709
DahuasecurityXvr-4x04 Firmware< 4.001.0000001.1.r.210709
DahuasecurityXvr-5x04 Firmware< 4.001.0000003.1.r.210710
DahuasecurityXvr-5x08 Firmware< 4.001.0000003.1.r.210710
DahuasecurityXvr-5x16 Firmware< 4.001.0000003.1.r.210710
DahuasecurityXvr-7x16 Firmware< 4.001.0000003.1.r.210710
DahuasecurityXvr-7x32 Firmware< 4.001.0000003.1.r.210710

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-33045?
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
How severe is CVE-2021-33045?
CVE-2021-33045 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 99.56% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2021-33045?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-33045?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST