7.5
CVSSv2

CVE-2021-33046

Published: 13/01/2022 Updated: 25/01/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dahuasecurity ipc-hx1xxx_firmware

dahuasecurity ipc-hx2xxx_firmware

dahuasecurity ipc-hx3xxx_firmware

dahuasecurity ipc-hx5\\(4\\)\\(3\\)xxx_firmware

dahuasecurity ipc-hx5xxx_firmware

dahuasecurity sd1a1_firmware

dahuasecurity sd22_firmware

dahuasecurity sd49_firmware

dahuasecurity sd50_firmware

dahuasecurity sd52c_firmware

dahuasecurity sd6al_firmware

dahuasecurity tpc-bf1241_firmware

dahuasecurity tpc-bf2221_firmware

dahuasecurity tpc-bf5x01_firmware

dahuasecurity tpc-pt8x21x_firmware

dahuasecurity tpc-sd2221_firmware

dahuasecurity tpc-sd8x21_firmware

dahuasecurity nvr1xxx_firmware

dahuasecurity nvr2xxx_firmware

dahuasecurity nvr4xxx_firmware

dahuasecurity nvr5xxx_firmware

dahuasecurity xvr4xxx_firmware

dahuasecurity xvr5xxx_firmware

dahuasecurity xvr7xxx_firmware

dahuasecurity hcvr7xxx_firmware

dahuasecurity hcvr8xxx_firmware

dahuasecurity vtox20xf_firmware

dahuasecurity asc2204c_firmware