CVE-2021-33044

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:ipc-hum7xxx:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dahuasecurity:sd1a1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd1a1:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dahuasecurity:sd22_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd22:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dahuasecurity:sd41_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd41:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-bf1241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-bf1241:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-bf2221_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-bf2221:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-bf5x01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-bf5x01:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-pt8x21b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-pt8x21b:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-sd2221_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-sd2221:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-sd8x21_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-sd8x21:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dahuasecurity:vto-65xxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:vto-65xxx:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dahuasecurity:vto-75x95x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:vto-75x95x:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dahuasecurity:vth-542xh_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:vth-542xh:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dahuasecurity:tpc-bf5x21_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dahuasecurity:tpc-bf5x21:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-09-15 22:15

Updated : 2024-08-22 01:00


NVD link : CVE-2021-33044

Mitre link : CVE-2021-33044

CVE.ORG link : CVE-2021-33044


JSON object : View

Products Affected

dahuasecurity

  • vto-65xxx_firmware
  • sd50
  • tpc-pt8x21b_firmware
  • tpc-sd8x21
  • sd1a1
  • sd52c_firmware
  • sd41
  • vto-75x95x_firmware
  • ipc-hum7xxx_firmware
  • sd52c
  • sd41_firmware
  • tpc-bf5x01_firmware
  • tpc-bf1241
  • sd1a1_firmware
  • tpc-bf2221_firmware
  • tpc-bf2221
  • tpc-bf5x21
  • ipc-hx5xxx_firmware
  • sd22_firmware
  • ipc-hx3xxx_firmware
  • ipc-hum7xxx
  • tpc-sd8x21_firmware
  • ipc-hx3xxx
  • sd6al
  • tpc-sd2221_firmware
  • sd50_firmware
  • sd6al_firmware
  • vto-65xxx
  • vth-542xh
  • sd22
  • tpc-pt8x21b
  • tpc-bf1241_firmware
  • vto-75x95x
  • tpc-sd2221
  • vth-542xh_firmware
  • ipc-hx5xxx
  • tpc-bf5x21_firmware
  • tpc-bf5x01
CWE
CWE-287

Improper Authentication