Skip to content
COOEY

EXPOSURES › CVE-2021-33045

CVE-2021-33045

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-33045 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedauth-bypass

Dahua IP cameras allow attackers to bypass authentication by specifying a loopback device, enabling unauthorized access to surveillance feeds.

This authentication bypass vulnerability allows attackers to bypass security controls on Dahua IP cameras by manipulating the loopback device parameter during authentication, potentially granting unauthorized access to surveillance feeds. DIB organizations must ensure all Dahua devices are patched and network segmentation is enforced to prevent unauthorized access to sensitive video data.

Shame score — A known authentication bypass vulnerability that was actively exploited but did not involve remote code execution or zero-day exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.