Evidence dossier

CVE-2021-33044

The identity authentication bypass vulnerability found in some Dahua products during the login process.

Exploited in the wild (CISA KEV since Aug 21, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 99.9% exploit likelihood as of Aug 26, 2026.

92.192.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

State
PUBLISHED
Published
Sep 15, 2021
Updated
Jan 12, 2026
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    dahua

    Record text: The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

    Inspect raw assertion
    Field
    container
    Value
    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Dahua IP Camera Authentication Bypass Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Dahua IP Camera Authentication Bypass Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.87% probability · 99.96th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.998710000000; percentile 0.999620000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Aug 21, 2024 · first observed Jul 19, 2026

Exploit likelihood99.87%

FIRST EPSS · score date Aug 26, 2026 · 100th percentile · first observed Aug 26, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
dahuaOriginal assertion
Record text

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Inspect raw assertion
Field
container
Value
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Dahua IP Camera Authentication Bypass Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Dahua IP Camera Authentication Bypass Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.87% probability · 99.96th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.998710000000; percentile 0.999620000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
38Underlying assertions
38Canonical products
19Target assertions
19Constraint assertions

Grouped from 38 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

39 scope groups

dahua · source assertedn/aSome Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devicesDirect source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, PTZ Dome Camera SD1A1, SD22, SD49, SD50, SD52C, and SD6AL, Thermal TPC-BF1241, TPC-BF2221, TPC-SD2221, TPC-BF5XXX, TPC-SD8X21, and TPC-PT8X21B devices Buildtime before June, 2021."}]
NVD CPE · HARDWAREdahuasecurityipc-hum7xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0b324caf3dae3219702267c9a2a87caddf5853fa49b32717441fbaea0bfdf15aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hum7xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ae9acb0-4cb3-4cf5-a007-15ee977d782e
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hum7xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.820.0000000.5.r.210705)Canonical identity product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22efLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.820.0000000.5.r.210705
    Match ID
    c0356805-3ecf-4c6f-b2bf-95d507736c44
NVD CPE · HARDWAREdahuasecurityipc-hx3xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-98608b4baf28cb9e54d1efb8f911625999a6adf89f0ba5c1faf03e3ce6bc1bb9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8936a118-4ab5-4b09-a9fd-e624a68315bd
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hx3xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.800.0000000.29.r.210630)Canonical identity product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.800.0000000.29.r.210630
    Match ID
    e0d17050-41ca-4808-8ed3-f332fd00b551
NVD CPE · HARDWAREdahuasecurityipc-hx5xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3962717b13ae9e96041309f6500006c82125a6268fbc1202ac3b39a45a1f1227Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2838bda-97ff-498e-bc81-955d31b9227a
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hx5xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.820.0000000.18.r.210705)Canonical identity product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.820.0000000.18.r.210705
    Match ID
    04346bb7-74d1-46c4-b058-076b16c0209f
NVD CPE · HARDWAREdahuasecuritysd1a1Environmental constraint · 1 assertions
Version not applicableCanonical identity product-f8761db0b3ceb70247135b0a9783f269ef3607664790a32c8ed6fbef1e5f5886Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd1a1:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88ad58de-d990-4c98-853b-21b79cd07eec
NVD CPE · OPERATING SYSTEMdahuasecuritysd1a1_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-e11b495c153246e8e5d32739fafc60123f6b2e1de849fb4ca69f0af7e85a2fe0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd1a1_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    4ba2ab22-37b0-471f-b6e4-bb3f3a6fb817
NVD CPE · HARDWAREdahuasecuritysd22Environmental constraint · 1 assertions
Version not applicableCanonical identity product-6831de10a4545bf5208c1416c4a5166b1c4de6f3f35a7cb098708365ed5d0641Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd22:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    428852de-bde3-4ce4-972c-821e88c7f930
NVD CPE · OPERATING SYSTEMdahuasecuritysd22_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-1db3e7a22ca432369eb7b7c339dda9c4da2095a6ae068ea8a428b95d92f92b09Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd22_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    17fadf4c-29f2-449a-b57e-59f2338d433c
NVD CPE · HARDWAREdahuasecuritysd49Environmental constraint · 1 assertions
Version not applicableCanonical identity product-276a16d70405d019b9921686a310f508d28b12eb49963bf36a13521c4de219e8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd49:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    627c0ae8-01b2-4807-8284-efe6140598b5
NVD CPE · OPERATING SYSTEMdahuasecuritysd49_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-6da0774bca1e0bce845e3b63613716641b7828f7fad79f12958b8ecaf524799cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd49_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    5efec730-5f5b-4b10-a843-f7d58d3ee543
NVD CPE · HARDWAREdahuasecuritysd50Environmental constraint · 1 assertions
Version not applicableCanonical identity product-a859ffb94003d5f2b407e1ecef0f83d4d73fa88047085835e74816480bfff81eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd50:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    984ad4d5-d689-4150-a1ee-d48b81cbb7c8
NVD CPE · OPERATING SYSTEMdahuasecuritysd50_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-9a178a987937ef92d9062aabf868efa6961e1a75d9672146b2f5d7cc7e2ca08dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd50_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    69712780-ba39-4b2e-810c-e9bcf6e213f1
NVD CPE · HARDWAREdahuasecuritysd52cEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cad50bc63633a545b3fe0b1dd8f7a2a4d76e8d303dc5a61a4c7c13e62ff0669eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd52c:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ba0d206-5be7-4592-8d3e-641f47164770
NVD CPE · OPERATING SYSTEMdahuasecuritysd52c_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-ceb7c3be10505ae5c46ce45809631c61b91db38c88abe8eb21c9b46da298b35fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd52c_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    69e7e0d4-7e9b-4580-b28a-898146ded548
NVD CPE · HARDWAREdahuasecuritysd6alEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-db5f2209910bfd939aeaba89d51727ce2b080c8b802a66019fd3c7dbc28a2a43Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:sd6al:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c35f4371-334b-4ea8-8f48-498c81652f7c
NVD CPE · OPERATING SYSTEMdahuasecuritysd6al_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.812.0000007.0.r.210706)Canonical identity product-30dfe2a5a47b45242c33604c23ac124ae4da5c986ab7544778b7725d3eb4f79fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:sd6al_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.812.0000007.0.r.210706
    Match ID
    41a67081-5051-47a0-a0ea-1c41a78f5c9a
NVD CPE · HARDWAREdahuasecuritytpc-bf1241Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4b192848bc9bf30ee59e28cf395c936330fd874d32e7b53cb7bdd1ae4fc9d53fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:tpc-bf1241:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73b58cbf-eb67-4f02-bbae-ffc329b8873c
NVD CPE · OPERATING SYSTEMdahuasecuritytpc-bf1241_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.630.0000000.6.r.210707)Canonical identity product-a1ad04755a88fafc24d8dfcfb773e4ad3d4ce949af039442fb2c1165b7e1a76dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:tpc-bf1241_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.630.0000000.6.r.210707
    Match ID
    468fd434-642e-4613-b720-84254d9b9960
NVD CPE · HARDWAREdahuasecuritytpc-bf2221Environmental constraint · 1 assertions
Version not applicableCanonical identity product-7238c9c40bb2350346922d4ad0de30a2d8a506c9ec4b71ebbf19c2b16aae66a3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:tpc-bf2221:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2e314bf6-76b4-4adb-b555-7daf92f60485
NVD CPE · OPERATING SYSTEMdahuasecuritytpc-bf2221_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.630.0000000.10.r.210707)Canonical identity product-3c12680e71809a847863c7ba4d3a5d0c78aade0ec32a50d78f46badb5d4e4fa1Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:tpc-bf2221_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.630.0000000.10.r.210707
    Match ID
    c24a62b1-effa-4d22-acb3-a645b325c280
NVD CPE · HARDWAREdahuasecuritytpc-bf5x01Environmental constraint · 1 assertions
Version not applicableCanonical identity product-b42ffca9d4afdb1a0924e5f71523b1455e9c90f49b355a49939e8a7ab3deec43Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:tpc-bf5x01:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f7ea0704-ec7a-457a-9ac1-a39b07229dfe
NVD CPE · OPERATING SYSTEMdahuasecuritytpc-bf5x01_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.630.0000000.12.r.210707)Canonical identity product-3197357632ec950cbe9b5e40999c8925a1f40570ca56d18ca7de5109470cdee9Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:tpc-bf5x01_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.630.0000000.12.r.210707
    Match ID
    c60703fa-f833-472c-84fc-2366409f484b

Affected-product evidence

Accepted scope and product mapping

19 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ae3d96f9-797b-4b51-92c6-ea37fd516588
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-1db3e7a22ca432369eb7b7c339dda9c4da2095a6ae068ea8a428b95d92f92b09

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9c063c79-efd0-44e2-9d62-1c3c967d9491
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-30dfe2a5a47b45242c33604c23ac124ae4da5c986ab7544778b7725d3eb4f79f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07211299-fc33-4f70-a0aa-e62050c0bb7c
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3197357632ec950cbe9b5e40999c8925a1f40570ca56d18ca7de5109470cdee9

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c50f5374-e251-47cf-a705-2b0ec9755f47
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3c12680e71809a847863c7ba4d3a5d0c78aade0ec32a50d78f46badb5d4e4fa1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
67d27bfa-00e9-4a7c-9f24-093ab9de31d2
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6da0774bca1e0bce845e3b63613716641b7828f7fad79f12958b8ecaf524799c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
49e88b77-e498-4eea-ac87-dfb0483d807e
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6ef3de059225454b6684b9bf14d465f59c9c6f9bee8ee3eb295e7c7696605e33

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a144b2c8-7429-4531-8f1c-6d03d21d9ede
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22ef

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e497b64e-e223-40f3-a2b1-712bad1f1a42
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-86ae60e5f5fde7ca39932c0acbba48b0c97d661e80a81ce6bcee98610580ac85

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a4bfd368-3ce6-4d33-b2af-9ef5c5c8f6da
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7c6a4477-17be-4992-bcee-ad161ebfe4fa
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-9a178a987937ef92d9062aabf868efa6961e1a75d9672146b2f5d7cc7e2ca08d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d126cd96-4ec6-4ce6-b2e5-14540c9d15d5
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-a1ad04755a88fafc24d8dfcfb773e4ad3d4ce949af039442fb2c1165b7e1a76d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1169ce4f-7d45-4857-9acd-56ffe40da130
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9c6b521d-1153-4056-983f-f6cc2857a9d5
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
62f1b751-8251-4d86-b48a-5a5b82e85fcc
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-bf2311039b407ef17819e68ca10c56f9c646b60ee4fd4f2ec12dc1682a852f2a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
28ef3e88-da2f-4521-bca0-a61019bfe644
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-ceb7c3be10505ae5c46ce45809631c61b91db38c88abe8eb21c9b46da298b35f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e4651543-0921-4103-8503-9eb46201df66
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b098973e-9b9a-4a34-9b1e-7dd610a8da00
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e11b495c153246e8e5d32739fafc60123f6b2e1de849fb4ca69f0af7e85a2fe0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18e838c7-a3d1-490d-8852-799513cc63d5
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-ea83353d4f60dcb5a4abcfc4a5de71b50fc85a6ee3c05e6d23e97166fdfb44ca

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
539880c5-f492-47b4-8922-44a674883ec9
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
05de21b4-faa2-493e-9513-9c9314211652

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.