CVE-2021-33046

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
13/01/2022
Last modified:
25/01/2022

Description

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dahuasecurity:ipc-hx1xxx_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:ipc-hx1xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx2xxx_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:ipc-hx2xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx5\(4\)\(3\)xxx_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:ipc-hx5\(4\)\(3\)xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd1a1_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:sd1a1:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd22_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)
cpe:2.3:h:dahuasecurity:sd22:-:*:*:*:*:*:*:*
cpe:2.3:o:dahuasecurity:sd49_firmware:*:*:*:*:*:*:*:* 2017-7 (including) 2021-7 (including)