CVE-2021-33046

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
dahuaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
dahuasecurityipc-hx1xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityipc-hx2xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityipc-hx3xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityipc-hx5\(4\)\(3\)xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityipc-hx5xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd1a1_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd22_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd49_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd50_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd52c_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritysd6al_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-bf1241_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-bf2221_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-bf5x01_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-pt8x21x_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-sd2221_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritytpc-sd8x21_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritynvr1xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritynvr2xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritynvr4xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecuritynvr5xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityxvr4xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityxvr5xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityxvr7xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityhcvr7xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityhcvr8xxx_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityvtox20xf_firmware
2017-7 ≤
𝑥
≤ 2021-7
dahuasecurityasc2204c_firmware
2017-7 ≤
𝑥
≤ 2021-7
𝑥
= Vulnerable software versions