Skip to content
COOEY

EXPOSURES › CVE-2021-33044

CVE-2021-33044

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-33044 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedauth-bypass

Dahua IP cameras allow attackers to bypass authentication by specifying a 'NetKeyboard' type argument, granting unauthorized access to device management.

This authentication bypass vulnerability allows attackers to bypass security controls on Dahua IP cameras, potentially enabling unauthorized access to video feeds and device management interfaces. For DIB organizations, this poses a significant risk as compromised cameras can be used to exfiltrate sensitive data or serve as entry points into broader networks, violating FedRAMP requirements for robust authentication mechanisms.

Shame score — The vulnerability was actively exploited and linked to ransomware campaigns, indicating a failure to patch a known issue promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.