boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-33045

n/a Some Dahua IP Camera, Video Intercom, NVR, XVR devices — Dahua IP Camera Firmware
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9959   99.9   YES
AFFECTED
  Product                                                 Versions                                                                                                                                                                                                                                                                               Fixed
  Some Dahua IP Camera, Video Intercom, NVR, XVR devices  Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019. –  —
TIMELINE
  May 17  Reserved by dahua
  Sep 15  Published (CNA: dahua)
  Aug 21  Added to CISA KEV, remediation due 2024-09-11
CWE-287 · CNA: dahua · CVSS v3.1 · 4 references · KEV due September 11, 2024

Description

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 17, 2021ReservedReserved by dahua
September 15, 2021PublishedPublished (CNA: dahua)
August 21, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-09-11

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
n/aSome Dahua IP Camera, Video Intercom, NVR, XVR devices—Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019.—

Weaknesses

CWE-287

References (4)

Related

Authoritative record: CVE-2021-33045 at cve.org

Weaknesses: CWE-287

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-33045 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.