CISA KEV · catalog date Aug 21, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-33044
The identity authentication bypass vulnerability found in some Dahua products during the login process.
Exploited in the wild (CISA KEV since Aug 21, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 99.9% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- State
- PUBLISHED
- Published
- Sep 15, 2021
- Updated
- Jan 12, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAdahuaOriginal evidence ↗
Record text: The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Inspect raw assertion
- Field
container- Value
- The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Dahua IP Camera Authentication Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dahua IP Camera Authentication Bypass Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.87% probability · 99.96th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.998710000000; percentile 0.999620000000
FIRST EPSS · score date Aug 26, 2026 · 100th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Inspect raw assertion
- Field
container- Value
- The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Dahua IP Camera Authentication Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dahua IP Camera Authentication Bypass Vulnerability
99.87% probability · 99.96th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.998710000000; percentile 0.999620000000
Applicability
Cited product scope
Grouped from 38 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
39 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, PTZ Dome Camera SD1A1, SD22, SD49, SD50, SD52C, and SD6AL, Thermal TPC-BF1241, TPC-BF2221, TPC-SD2221, TPC-BF5XXX, TPC-SD8X21, and TPC-PT8X21B devices Buildtime before June, 2021."}]product-0b324caf3dae3219702267c9a2a87caddf5853fa49b32717441fbaea0bfdf15aLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hum7xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5ae9acb0-4cb3-4cf5-a007-15ee977d782e
product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22efLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.820.0000000.5.r.210705
- Match ID
c0356805-3ecf-4c6f-b2bf-95d507736c44
product-98608b4baf28cb9e54d1efb8f911625999a6adf89f0ba5c1faf03e3ce6bc1bb9Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8936a118-4ab5-4b09-a9fd-e624a68315bd
product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.800.0000000.29.r.210630
- Match ID
e0d17050-41ca-4808-8ed3-f332fd00b551
product-3962717b13ae9e96041309f6500006c82125a6268fbc1202ac3b39a45a1f1227Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2838bda-97ff-498e-bc81-955d31b9227a
product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02fLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.820.0000000.18.r.210705
- Match ID
04346bb7-74d1-46c4-b058-076b16c0209f
product-f8761db0b3ceb70247135b0a9783f269ef3607664790a32c8ed6fbef1e5f5886Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd1a1:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
88ad58de-d990-4c98-853b-21b79cd07eec
product-e11b495c153246e8e5d32739fafc60123f6b2e1de849fb4ca69f0af7e85a2fe0Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd1a1_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
4ba2ab22-37b0-471f-b6e4-bb3f3a6fb817
product-6831de10a4545bf5208c1416c4a5166b1c4de6f3f35a7cb098708365ed5d0641Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd22:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
428852de-bde3-4ce4-972c-821e88c7f930
product-1db3e7a22ca432369eb7b7c339dda9c4da2095a6ae068ea8a428b95d92f92b09Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd22_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
17fadf4c-29f2-449a-b57e-59f2338d433c
product-276a16d70405d019b9921686a310f508d28b12eb49963bf36a13521c4de219e8Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd49:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
627c0ae8-01b2-4807-8284-efe6140598b5
product-6da0774bca1e0bce845e3b63613716641b7828f7fad79f12958b8ecaf524799cLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd49_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
5efec730-5f5b-4b10-a843-f7d58d3ee543
product-a859ffb94003d5f2b407e1ecef0f83d4d73fa88047085835e74816480bfff81eLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
984ad4d5-d689-4150-a1ee-d48b81cbb7c8
product-9a178a987937ef92d9062aabf868efa6961e1a75d9672146b2f5d7cc7e2ca08dLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
69712780-ba39-4b2e-810c-e9bcf6e213f1
product-cad50bc63633a545b3fe0b1dd8f7a2a4d76e8d303dc5a61a4c7c13e62ff0669eLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5ba0d206-5be7-4592-8d3e-641f47164770
product-ceb7c3be10505ae5c46ce45809631c61b91db38c88abe8eb21c9b46da298b35fLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
69e7e0d4-7e9b-4580-b28a-898146ded548
product-db5f2209910bfd939aeaba89d51727ce2b080c8b802a66019fd3c7dbc28a2a43Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c35f4371-334b-4ea8-8f48-498c81652f7c
product-30dfe2a5a47b45242c33604c23ac124ae4da5c986ab7544778b7725d3eb4f79fLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.812.0000007.0.r.210706
- Match ID
41a67081-5051-47a0-a0ea-1c41a78f5c9a
product-4b192848bc9bf30ee59e28cf395c936330fd874d32e7b53cb7bdd1ae4fc9d53fLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:tpc-bf1241:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
73b58cbf-eb67-4f02-bbae-ffc329b8873c
product-a1ad04755a88fafc24d8dfcfb773e4ad3d4ce949af039442fb2c1165b7e1a76dLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:tpc-bf1241_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.630.0000000.6.r.210707
- Match ID
468fd434-642e-4613-b720-84254d9b9960
product-7238c9c40bb2350346922d4ad0de30a2d8a506c9ec4b71ebbf19c2b16aae66a3Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:tpc-bf2221:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e314bf6-76b4-4adb-b555-7daf92f60485
product-3c12680e71809a847863c7ba4d3a5d0c78aade0ec32a50d78f46badb5d4e4fa1Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:tpc-bf2221_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.630.0000000.10.r.210707
- Match ID
c24a62b1-effa-4d22-acb3-a645b325c280
product-b42ffca9d4afdb1a0924e5f71523b1455e9c90f49b355a49939e8a7ab3deec43Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:tpc-bf5x01:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f7ea0704-ec7a-457a-9ac1-a39b07229dfe
product-3197357632ec950cbe9b5e40999c8925a1f40570ca56d18ca7de5109470cdee9Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:tpc-bf5x01_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.630.0000000.12.r.210707
- Match ID
c60703fa-f833-472c-84fc-2366409f484b
Affected-product evidence
Accepted scope and product mapping
19 canonical links · 1 source-reported links
vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ae3d96f9-797b-4b51-92c6-ea37fd516588vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-1db3e7a22ca432369eb7b7c339dda9c4da2095a6ae068ea8a428b95d92f92b09
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9c063c79-efd0-44e2-9d62-1c3c967d9491vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-30dfe2a5a47b45242c33604c23ac124ae4da5c986ab7544778b7725d3eb4f79f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07211299-fc33-4f70-a0aa-e62050c0bb7cvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3197357632ec950cbe9b5e40999c8925a1f40570ca56d18ca7de5109470cdee9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c50f5374-e251-47cf-a705-2b0ec9755f47vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3c12680e71809a847863c7ba4d3a5d0c78aade0ec32a50d78f46badb5d4e4fa1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
67d27bfa-00e9-4a7c-9f24-093ab9de31d2vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6da0774bca1e0bce845e3b63613716641b7828f7fad79f12958b8ecaf524799c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
49e88b77-e498-4eea-ac87-dfb0483d807evendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6ef3de059225454b6684b9bf14d465f59c9c6f9bee8ee3eb295e7c7696605e33
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a144b2c8-7429-4531-8f1c-6d03d21d9edevendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e497b64e-e223-40f3-a2b1-712bad1f1a42vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-86ae60e5f5fde7ca39932c0acbba48b0c97d661e80a81ce6bcee98610580ac85
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a4bfd368-3ce6-4d33-b2af-9ef5c5c8f6davendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7c6a4477-17be-4992-bcee-ad161ebfe4favendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-9a178a987937ef92d9062aabf868efa6961e1a75d9672146b2f5d7cc7e2ca08d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d126cd96-4ec6-4ce6-b2e5-14540c9d15d5vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-a1ad04755a88fafc24d8dfcfb773e4ad3d4ce949af039442fb2c1165b7e1a76d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1169ce4f-7d45-4857-9acd-56ffe40da130vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9c6b521d-1153-4056-983f-f6cc2857a9d5vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
62f1b751-8251-4d86-b48a-5a5b82e85fccvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-bf2311039b407ef17819e68ca10c56f9c646b60ee4fd4f2ec12dc1682a852f2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
28ef3e88-da2f-4521-bca0-a61019bfe644vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-ceb7c3be10505ae5c46ce45809631c61b91db38c88abe8eb21c9b46da298b35f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e4651543-0921-4103-8503-9eb46201df66vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b098973e-9b9a-4a34-9b1e-7dd610a8da00vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e11b495c153246e8e5d32739fafc60123f6b2e1de849fb4ca69f0af7e85a2fe0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18e838c7-a3d1-490d-8852-799513cc63d5vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-ea83353d4f60dcb5a4abcfc4a5de71b50fc85a6ee3c05e6d23e97166fdfb44ca
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
539880c5-f492-47b4-8922-44a674883ec9Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
05de21b4-faa2-493e-9513-9c9314211652Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.