EXPOSURES › CVE-2021-33044
CVE-2021-33044
HIGH ⌖ ON CISA KEV · EXPLOITEDDahua IP cameras allow attackers to bypass authentication by specifying a 'NetKeyboard' type argument, granting unauthorized access to device management.
This authentication bypass vulnerability allows attackers to bypass security controls on Dahua IP cameras, potentially enabling unauthorized access to video feeds and device management interfaces. For DIB organizations, this poses a significant risk as compromised cameras can be used to exfiltrate sensitive data or serve as entry points into broader networks, violating FedRAMP requirements for robust authentication mechanisms.
Shame score — The vulnerability was actively exploited and linked to ransomware campaigns, indicating a failure to patch a known issue promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.