EXPOSURES › CVE-2021-33045
CVE-2021-33045
HIGH ⌖ ON CISA KEV · EXPLOITEDDahua IP cameras allow attackers to bypass authentication by specifying a loopback device, enabling unauthorized access to surveillance feeds.
This authentication bypass vulnerability allows attackers to bypass security controls on Dahua IP cameras by manipulating the loopback device parameter during authentication, potentially granting unauthorized access to surveillance feeds. DIB organizations must ensure all Dahua devices are patched and network segmentation is enforced to prevent unauthorized access to sensitive video data.
Shame score — A known authentication bypass vulnerability that was actively exploited but did not involve remote code execution or zero-day exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.