PT-2021-20027 · Dahua · Dahua Ip Camera
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dahua ipc-hum7xxx firmware
Dahua ipc-hx3xxx firmware
Dahua ipc-hx5xxx firmware
Dahua sd1a1 firmware
Dahua sd22 firmware
Dahua sd49 firmware
Dahua sd50 firmware
Dahua sd52c firmware
Dahua sd6al firmware
Dahua tpc-bf1241 firmware
Dahua tpc-bf2221 firmware
Dahua tpc-bf5x01 firmware
Dahua tpc-bf5x21 firmware
Dahua tpc-pt8x21b firmware
Dahua tpc-sd2221 firmware
Dahua tpc-sd8x21 firmware
Dahua vth-542xh firmware
Dahua vto-65xxx firmware
Dahua vto-75x95x firmware
Description
An identity authentication bypass exists during the login process. Remote attackers can bypass device identity authentication by constructing malicious data packets. This issue is related to flaws in the authentication procedures of the Loopback mechanism and the
RPC2 Login web interface authentication mechanism, which may allow an attacker to escalate privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dahua Ip Camera