First published: Wed Sep 15 2021(Updated: )
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
Credit: cybersecurity@dahuatech.com cybersecurity@dahuatech.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dahuasecurity Ipc-hum7xxx Firmware | <2.820.0000000.5.r.210705 | |
Dahuasecurity Ipc-hum7xxx | ||
Dahuasecurity Ipc-hx3xxx Firmware | <2.800.0000000.29.r.210630 | |
Dahuasecurity Ipc-hx3xxx | ||
Dahuasecurity Ipc-hx5xxx Firmware | <2.820.0000000.5.r.210705 | |
Dahuasecurity Ipc-hx5xxx | ||
Dahuasecurity Nvr-1xxx Firmware | <4.001.0000005.1.r.210709 | |
Dahuasecurity Nvr-1xxx | ||
Dahuasecurity Nvr-2xxx Firmware | <4.001.0000000.1.r.210710 | |
Dahuasecurity Nvr-2xxx | ||
Dahuasecurity Nvr-4xxx Firmware | <4.001.0000005.1.r.210713 | |
Dahuasecurity Nvr-4xxx | ||
Dahuasecurity Nvr-5xxx Firmware | <4.001.0000000.0.r.210710 | |
Dahuasecurity Nvr-5xxx | ||
Dahuasecurity Nvr-6xx Firmware | <4.001.0000001.1.r.210716 | |
Dahuasecurity Nvr-6xx | ||
Dahuasecurity Vth-542xh Firmware | <4.500.0000002.0.r.210715 | |
Dahuasecurity Vth-542xh | ||
Dahuasecurity Vto-65xxx Firmware | <4.300.0000004.0.r.210715 | |
Dahuasecurity Vto-65xxx | ||
Dahuasecurity Vto-75x95x Firmware | <4.300.0000003.0.r.210714 | |
Dahuasecurity Vto-75x95x | ||
Dahuasecurity Xvr-4x04 Firmware | ||
Dahuasecurity Xvr-4x04 | ||
Dahuasecurity Xvr-4x08 Firmware | <4.001.0000001.1.r.210709 | |
Dahuasecurity Xvr-4x08 | ||
Dahuasecurity Xvr-4x04 Firmware | <4.001.0000001.1.r.210709 | |
Dahuasecurity Xvr-5x04 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x04 | ||
Dahuasecurity Xvr-5x08 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x08 | ||
Dahuasecurity Xvr-5x16 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x16 | ||
Dahuasecurity Xvr-7x16 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-7x16 | ||
Dahuasecurity Xvr-7x32 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-7x32 | ||
All of | ||
Dahuasecurity Ipc-hum7xxx Firmware | <2.820.0000000.5.r.210705 | |
Dahuasecurity Ipc-hum7xxx | ||
All of | ||
Dahuasecurity Ipc-hx3xxx Firmware | <2.800.0000000.29.r.210630 | |
Dahuasecurity Ipc-hx3xxx | ||
All of | ||
Dahuasecurity Ipc-hx5xxx Firmware | <2.820.0000000.5.r.210705 | |
Dahuasecurity Ipc-hx5xxx | ||
All of | ||
Dahuasecurity Nvr-1xxx Firmware | <4.001.0000005.1.r.210709 | |
Dahuasecurity Nvr-1xxx | ||
All of | ||
Dahuasecurity Nvr-2xxx Firmware | <4.001.0000000.1.r.210710 | |
Dahuasecurity Nvr-2xxx | ||
All of | ||
Dahuasecurity Nvr-4xxx Firmware | <4.001.0000005.1.r.210713 | |
Dahuasecurity Nvr-4xxx | ||
All of | ||
Dahuasecurity Nvr-5xxx Firmware | <4.001.0000000.0.r.210710 | |
Dahuasecurity Nvr-5xxx | ||
All of | ||
Dahuasecurity Nvr-6xx Firmware | <4.001.0000001.1.r.210716 | |
Dahuasecurity Nvr-6xx | ||
All of | ||
Dahuasecurity Vth-542xh Firmware | <4.500.0000002.0.r.210715 | |
Dahuasecurity Vth-542xh | ||
All of | ||
Dahuasecurity Vto-65xxx Firmware | <4.300.0000004.0.r.210715 | |
Dahuasecurity Vto-65xxx | ||
All of | ||
Dahuasecurity Vto-75x95x Firmware | <4.300.0000003.0.r.210714 | |
Dahuasecurity Vto-75x95x | ||
All of | ||
Dahuasecurity Xvr-4x04 Firmware | ||
Dahuasecurity Xvr-4x04 | ||
All of | ||
Dahuasecurity Xvr-4x08 Firmware | <4.001.0000001.1.r.210709 | |
Dahuasecurity Xvr-4x08 | ||
All of | ||
Dahuasecurity Xvr-4x04 Firmware | <4.001.0000001.1.r.210709 | |
Dahuasecurity Xvr-4x04 | ||
All of | ||
Dahuasecurity Xvr-5x04 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x04 | ||
All of | ||
Dahuasecurity Xvr-5x08 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x08 | ||
All of | ||
Dahuasecurity Xvr-5x16 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-5x16 | ||
All of | ||
Dahuasecurity Xvr-7x16 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-7x16 | ||
All of | ||
Dahuasecurity Xvr-7x32 Firmware | <4.001.0000003.1.r.210710 | |
Dahuasecurity Xvr-7x32 | ||
Dahua IP Camera Firmware | ||
All of | ||
<2.820.0000000.5.r.210705 | ||
All of | ||
<2.800.0000000.29.r.210630 | ||
All of | ||
<2.820.0000000.5.r.210705 | ||
All of | ||
<4.001.0000005.1.r.210709 | ||
All of | ||
<4.001.0000000.1.r.210710 | ||
All of | ||
<4.001.0000005.1.r.210713 | ||
All of | ||
<4.001.0000000.0.r.210710 | ||
All of | ||
<4.001.0000001.1.r.210716 | ||
All of | ||
<4.500.0000002.0.r.210715 | ||
All of | ||
<4.300.0000004.0.r.210715 | ||
All of | ||
<4.300.0000003.0.r.210714 | ||
All of | ||
All of | ||
<4.001.0000001.1.r.210709 | ||
All of | ||
<4.001.0000001.1.r.210709 | ||
All of | ||
<4.001.0000003.1.r.210710 | ||
All of | ||
<4.001.0000003.1.r.210710 | ||
All of | ||
<4.001.0000003.1.r.210710 | ||
All of | ||
<4.001.0000003.1.r.210710 | ||
All of | ||
<4.001.0000003.1.r.210710 | ||
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33045 refers to the identity authentication bypass vulnerability found in some Dahua products during the login process.
CVE-2021-33045 has a severity rating of 9.8, indicating a critical vulnerability.
Dahua products such as Dahuasecurity Ipc-hum7xxx Firmware, Dahuasecurity Ipc-hx3xxx Firmware, Dahuasecurity Ipc-hx5xxx Firmware, Dahuasecurity Nvr-1xxx Firmware, Dahuasecurity Nvr-2xxx Firmware, Dahuasecurity Nvr-4xxx Firmware, Dahuasecurity Nvr-5xxx Firmware, Dahuasecurity Nvr-6xx Firmware, Dahuasecurity Vth-542xh Firmware, Dahuasecurity Vto-65xxx Firmware, Dahuasecurity Vto-75x95x Firmware, Dahuasecurity Xvr-4x08 Firmware, Dahuasecurity Xvr-5x04 Firmware, Dahuasecurity Xvr-5x08 Firmware, Dahuasecurity Xvr-5x16 Firmware, Dahuasecurity Xvr-7x16 Firmware, and Dahuasecurity Xvr-7x32 Firmware may be affected.
An attacker can exploit CVE-2021-33045 by bypassing device identity authentication using malicious data packets.
You can find more information about CVE-2021-33045 on the Dahua Security website.