SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33046

Some Dahua products have access control vulnerability in the password reset process.

CRITICAL 9.8EPSS 1.30%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.30% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
dahuasecurity/ipc-hx1xxx firmware · dahuasecurity/ipc-hx2xxx firmware · dahuasecurity/ipc-hx3xxx firmware · dahuasecurity/ipc-hx5\(4\)\(3\)xxx firmware · dahuasecurity/ipc-hx5xxx firmware · dahuasecurity/sd1a1 firmware · dahuasecurity/sd22 firmware · dahuasecurity/sd49 firmware · dahuasecurity/sd50 firmware · dahuasecurity/sd52c firmware · dahuasecurity/sd6al firmware · dahuasecurity/tpc-bf1241 firmware · dahuasecurity/tpc-bf2221 firmware · dahuasecurity/tpc-bf5x01 firmware · dahuasecurity/tpc-pt8x21x firmware · dahuasecurity/tpc-sd2221 firmware · dahuasecurity/tpc-sd8x21 firmware · dahuasecurity/nvr1xxx firmware · dahuasecurity/nvr2xxx firmware · dahuasecurity/nvr4xxx firmware · +8 more
Source
cybersecurity@dahuatech.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.