CVE-2021-33044 - Dahua IP Camera Authentication Bypass Vulnerability
Project:Dahua
Product:IP Camera Firmware
Date Added:2024-08-21Due Date:2024-09-11
Vulnerability Name
Dahua IP Camera Authentication Bypass Vulnerability
Description
Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582
https://nvd.nist.gov/vuln/detail/CVE-2021-33044
Related News Articles
CISA and FBI Raise Alerts on Exploited Flaws and Expanding HiatusRAT CampaignDecember 17, 2024
FBI spots HiatusRAT malware attacks targeting web cameras, DVRsDecember 17, 2024
CISA Urges Federal Agencies to Patch Versa Director Vulnerability by SeptemberAugust 24, 2024