-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Created CVE-2021-33045.yaml (Dahua IPC/VTH/VTO - Authentication Bypass) KEV #12296
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Created CVE-2021-33045.yaml (Dahua IPC/VTH/VTO - Authentication Bypass) KEV #12296
Conversation
Template / PR Information Create CVE-2021-33045.yaml Template Validation I've validated this template locally? YES Additional Details (leave it blank if not applicable) Additional References: - https://nvd.nist.gov/vuln/detail/cve-2021-33045 - https://seclists.org/fulldisclosure/2021/Oct/13
|
Hi. Is anything wrong with this PR? |
|
Hi @cybermorgue, Is there any documentation or setup instructions available for deploying the vulnerable environment or running the software locally? Also, if you have any sample data that could help with debugging, that would be greatly appreciated. Thanks |
|
Hi @DhiyaneshGeek, I'm afraid it's not possible to provide documentation, setup instructions, or sample data for this finding. This was an IP Camera discovered during an external penetration test, meaning it's a physical device accessible from the internet, not a replicable environment or software that can be run locally. This is the repo for the exploit in which the template is based: https://github.com/mcw0/DahuaConsole I hope this clarifies the situation. Thanks. |
|
Hello. More info? Thank you. |
|
Hi @cybermorgue we are looking into this Thanks for the script ! |
|
Hi @cybermorgue i have made some changes to the template, let me know if it looks good ! Thank you so much for sharing this template with the community and contributing to this project 🍻 You can grab some cool PD stickers over here http://nux.gg/stickers 😄 You can join our discord server. It's a great place to connect with fellow contributors and stay updated with the latest developments. Thank you once again |
Template / PR Information
Created CVE 2021 33045 template. A vulnerability in Dahua Cam for Authentication Bypass.
Template Validation
I've validated this template locally?
Additional References
https://nvd.nist.gov/vuln/detail/cve-2021-33045