PT-2021-20028 · Dahua · Dahua Ip Camera
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dahua ipc-hum7xxx firmware
Dahua ipc-hx3xxx firmware
Dahua ipc-hx5xxx firmware
Dahua nvr-1xxx firmware
Dahua nvr-2xxx firmware
Dahua nvr-4xxx firmware
Dahua nvr-5xxx firmware
Dahua nvr-6xx firmware
Dahua vth-542xh firmware
Dahua vto-65xxx firmware
Dahua vto-75x95x firmware
Dahua xvr-4x04 firmware
Dahua xvr-4x08 firmware
Dahua xvr-5x04 firmware
Dahua xvr-5x08 firmware
Dahua xvr-5x16 firmware
Dahua xvr-7x16 firmware
Dahua xvr-7x32 firmware
Description
An identity authentication bypass exists during the login process. Attackers can bypass the device identity authentication by constructing and sending malicious data packets.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dahua Ip Camera