CVE-2021-33044 is a critical identity authentication bypass vulnerability affecting various Dahua products, including IP cameras, allowing attackers to bypass login authentication by crafting malicious data packets. This vulnerability carries a CVSS score of 9.8, indicating a critical severity with a network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as evidenced by its inclusion in the KEV catalog and mentions of its use in HiatusRAT malware attacks, with Nuclei templates available for detection and significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.820.0000000.5.r.210705CPE matchmatch criteria | cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:* | ||
< 2.800.0000000.29.r.210630CPE matchmatch criteria | cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:* | ||
< 2.820.0000000.18.r.210705CPE matchmatch criteria | cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:* | ||
< 2.812.0000007.0.r.210706CPE matchmatch criteria | cpe:2.3:o:dahuasecurity:sd1a1_firmware:*:*:*:*:*:*:*:* | ||
< 2.812.0000007.0.r.210706CPE matchmatch criteria | cpe:2.3:o:dahuasecurity:sd22_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.