The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Is CVE-2021-33044 exploited?
Listed in the CISA KEV catalog on 2024-08-21.
Federal remediation due 2024-09-11.
Past that date by 707 days.
EPSS puts exploitation in the next 30 days at 99.9%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devices · Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, PTZ Dome Camera SD1A1, SD22, SD49, SD50, SD52C, and SD6AL, Thermal TPC-BF1241, TPC-BF2221, TPC-SD2221, TPC-BF5XXX, TPC-SD8X21, and TPC-PT8X21B devices Buildtime before June, 2021.