CVE-2021-33046
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
Affected (28)
Products: Dahuasecurity: Ipc Hx1xxx Firmware, Ipc Hx2xxx Firmware, Ipc Hx3xxx Firmware, Ipc Hx5(4)(3)xxx Firmware, Ipc Hx5xxx Firmware, Sd1a1 Firmware, Sd22 Firmware, Sd49 Firmware, Sd50 Firmware, Sd52c Firmware, Sd6al Firmware, Tpc Bf1241 Firmware, Tpc Bf2221 Firmware, Tpc Bf5x01 Firmware, Tpc Pt8x21x Firmware, Tpc Sd2221 Firmware, Tpc Sd8x21 Firmware, Nvr1xxx Firmware, Nvr2xxx Firmware, Nvr4xxx Firmware, Nvr5xxx Firmware, Xvr4xxx Firmware, Xvr5xxx Firmware, Xvr7xxx Firmware, Hcvr7xxx Firmware, Hcvr8xxx Firmware, Vtox20xf Firmware, Asc2204c Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx1xxx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx2xxx | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx3xxx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx5(4)(3)xxx | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Ipc Hx5xxx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd1a1 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd22 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd49 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd50 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd52c | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Sd6al | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Bf1241 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Bf2221 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Bf5x01 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Pt8x21x | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Sd2221 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Tpc Sd8x21 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr1xxx | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr2xxx | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr4xxx | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Nvr5xxx | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Xvr4xxx | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Xvr5xxx | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Xvr7xxx | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Hcvr7xxx | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Hcvr8xxx | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Vtox20xf | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2017-7 to 2021-7 |
| Running on/with | Platform Versions |
|---|---|
Dahuasecurity Asc2204c | All versions |
References (6)
Source: cybersecurity@dahuatech.com
Vendor Advisory
Source: cybersecurity@dahuatech.com
Not Applicable
Source: cybersecurity@dahuatech.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.