【Vulnerability Alert】High-Risk Security Vulnerabilities in Dahua IP Camera (CVE-2021-33044 and CVE-2021-33045) - Please Verify and Patch Immediately!

publish date : 2024-09-02 update date : 2024-09-02

Source: Ministry of education information & communication security contingency platform

Publication Number TACERT-ANA-2024082901082626 Publication Time 2024/08/29 13:09
Incident Type ANA-Vulnerability Alert Discovery Time 2024/08/29 12:50
Impact Level Medium  
[Subject]
【Vulnerability Alert】High-Risk Security Vulnerabilities in Dahua IP Camera (CVE-2021-33044 and CVE-2021-33045) - Please Verify and Patch Immediately!
[Content]
Forwarded from the National Institute of Cyber Security NISAC-200-202408-00000062

Recently, researchers have observed attacks exploiting previously discovered critical vulnerabilities. Certain Dahua IP Cameras contain Authentication Bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045). These vulnerabilities allow remote attackers to bypass authentication and directly access affected devices. Please verify and apply patches immediately.

Information Sharing Level: WHITE (Information content can be publicly disclosed)
[Affected Platform]
● DHI-ASI7213Y-V3-T1
● IPC-HUM7XXX IPC-HX1XXX
● IPC-HX2XXX IPC-HX3XXX
● IPC-HX5(4)(3)XXX IPC-HX5XXX
● IPC-HX8XXX
● NVR1XXX
● NVR2XXX
● NVR5XXX
● NVR6XX
● PTZ Dome Camera SD1A1
● PTZ Dome Camera SD22
● PTZ Dome Camera SD49
● PTZ Dome Camera SD50
● PTZ Dome Camera SD52C
● PTZ Dome Camera SD6AL
● Thermal TPC-BF1241
● Thermal TPC-BF2221
● Thermal TPC-BF5XXX
● Thermal TPC-PT8X21B
● Thermal TPC-SD2221
● Thermal TPC-SD8X21
● VTH542XH
● VTO65XXX
● VTO75X95X
● XVR4xxx
● XVR5xxx
● XVR7xxx
[Recommended Actions]
A patch has been released to address these vulnerabilities. Please refer to the official documentation and update accordingly at the following URL:
https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582
[Reference]
1. https://nvd.nist.gov/vuln/detail/CVE-2021-33044
2. https://nvd.nist.gov/vuln/detail/CVE-2021-33045
3. https://www.dahuasecurity.com/aboutUs/trustedCenter/details/582
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center