The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Is CVE-2021-33045 exploited?
Listed in the CISA KEV catalog on 2024-08-21.
Federal remediation due 2024-09-11.
Past that date by 707 days.
EPSS puts exploitation in the next 30 days at 99.6%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
Some Dahua IP Camera, Video Intercom, NVR, XVR devices · Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019.