CRITICAL

CVE-2021-33045

Dahuasecurity Ipc Hum7xxx Firmware 2021-09-15 CVSS v3.1
CVSS
9.8
KEV

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Summary dbcve.org

This is an authentication bypass vulnerability in Dahua security products (likely IP cameras, NVRs, and similar devices) where the login process fails to properly validate identity credentials. Attackers can craft malicious data packets to circumvent the authentication mechanism and gain unauthorized access to the device without valid credentials.

Mitigation

Apply vendor-supplied firmware patches immediately. If patches are unavailable, restrict network access to affected devices using firewalls or VLANs, and monitor for unauthorized access attempts.

Proof of Concept

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

99.59%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE