VulnerabilityModified
CVE-2021-33046
Some Dahua products have access control vulnerability in the password reset process.
CRITICAL 9.8EPSS 1.30%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- dahuasecurity/ipc-hx1xxx firmware · dahuasecurity/ipc-hx2xxx firmware · dahuasecurity/ipc-hx3xxx firmware · dahuasecurity/ipc-hx5\(4\)\(3\)xxx firmware · dahuasecurity/ipc-hx5xxx firmware · dahuasecurity/sd1a1 firmware · dahuasecurity/sd22 firmware · dahuasecurity/sd49 firmware · dahuasecurity/sd50 firmware · dahuasecurity/sd52c firmware · dahuasecurity/sd6al firmware · dahuasecurity/tpc-bf1241 firmware · dahuasecurity/tpc-bf2221 firmware · dahuasecurity/tpc-bf5x01 firmware · dahuasecurity/tpc-pt8x21x firmware · dahuasecurity/tpc-sd2221 firmware · dahuasecurity/tpc-sd8x21 firmware · dahuasecurity/nvr1xxx firmware · dahuasecurity/nvr2xxx firmware · dahuasecurity/nvr4xxx firmware · +8 more
- Source
- cybersecurity@dahuatech.com
References
- https://support.dahuatech.com/networkSecurity/securityDetails?id=95Vendor Advisory
- https://www.dahuasecurity.com/support/cybersecurity/details/957Not Applicable
- https://www.dahuasecurity.com/support/cybersecurity/details/987Vendor Advisory
- https://support.dahuatech.com/networkSecurity/securityDetails?id=95Vendor Advisory
- https://www.dahuasecurity.com/support/cybersecurity/details/957Not Applicable
- https://www.dahuasecurity.com/support/cybersecurity/details/987Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.