CISA KEV · catalog date Aug 21, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-33045
The identity authentication bypass vulnerability found in some Dahua products during the login process.
Exploited in the wild (CISA KEV since Aug 21, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 99.6% exploit likelihood as of Aug 18, 2026.
As of Aug 27, 2026
Normalized restatement
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- State
- PUBLISHED
- Published
- Sep 15, 2021
- Updated
- Jan 12, 2026
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAdahuaOriginal evidence ↗
Record text: The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Inspect raw assertion
- Field
container- Value
- The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Dahua IP Camera Authentication Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dahua IP Camera Authentication Bypass Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.56% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.995560000000; percentile 0.999440000000
FIRST EPSS · score date Aug 18, 2026 · 99.9th percentile · first observed Aug 18, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Inspect raw assertion
- Field
container- Value
- The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Dahua IP Camera Authentication Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Dahua IP Camera Authentication Bypass Vulnerability
99.56% probability · 99.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.995560000000; percentile 0.999440000000
Applicability
Cited product scope
Grouped from 38 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
37 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019."}]product-0b324caf3dae3219702267c9a2a87caddf5853fa49b32717441fbaea0bfdf15aLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hum7xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5ae9acb0-4cb3-4cf5-a007-15ee977d782e
product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22efLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.820.0000000.5.r.210705
- Match ID
c0356805-3ecf-4c6f-b2bf-95d507736c44
product-98608b4baf28cb9e54d1efb8f911625999a6adf89f0ba5c1faf03e3ce6bc1bb9Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8936a118-4ab5-4b09-a9fd-e624a68315bd
product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.800.0000000.29.r.210630
- Match ID
e0d17050-41ca-4808-8ed3-f332fd00b551
product-3962717b13ae9e96041309f6500006c82125a6268fbc1202ac3b39a45a1f1227Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2838bda-97ff-498e-bc81-955d31b9227a
product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02fLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.820.0000000.5.r.210705
- Match ID
3f20dc69-b735-4547-826d-e4c42a39fe82
product-528fb3e4e84a7f68366acd20796cf90c1d5508f9807a92aa44e66c794261fdfeLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:nvr-1xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7780d1be-abe0-4890-b493-36fa0a4b3266
product-6c4f2d4eea70c68b7b05cdbfdbc39933eaac44650b805ee8dc5f6fe27a2c0e02Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:nvr-1xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000005.1.r.210709
- Match ID
fa1c3935-c83b-4a1a-beee-ef93f7722972
product-cefaf7c4ddce9bd8c898f71e21f089b7774fc4d3a8b843519cb36d440bd743bcLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:nvr-2xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
89e3f7b3-3c51-49c1-baec-da4235d5a06d
product-c8f856c2a909a349827cb8848b58fe6397c5f2756d99796025751d7395d981f0Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:nvr-2xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000000.1.r.210710
- Match ID
795ef8b2-5e6d-46eb-9f66-85f2c71b2619
product-26b2d11926ebea5922f643367cecd76fd701da450adffead82c7c1c782895723Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:nvr-4xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58ecdc49-09d4-4e62-ac11-e3c52c656a9d
product-7d7db0eea822e6e5114d08258625df5cff36fc3cf5b01f86dffc10068a99a0a2Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:nvr-4xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000005.1.r.210713
- Match ID
1386662b-c3de-467a-8f41-f18bde7b9726
product-8f92c1e4b7d1edbe5ba2b824ca7a63665261da226c2463e3a382555d2105b573Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:nvr-5xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
de621958-8ae2-44e0-9e41-94bc964cdf57
product-0206f23d31f14765aa36f952936cc31572c1df82c74e6ad6f8f2fbe4995a69b3Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:nvr-5xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000000.0.r.210710
- Match ID
06a6b28a-2e0d-4e45-904a-66fee5d85262
product-3c9e928c71879e62087b4f519c51f51a7399d7e2786a6daf0547532bfe132a91Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:nvr-6xx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9eeac798-870e-4de6-b7db-44faf5360ce5
product-c6fd4d04b4bfa52a47d8928f5c143ec7b165ee4133c59fd4ab9e0cfeb5b70aeaLinked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:nvr-6xx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000001.1.r.210716
- Match ID
90d5a1b3-88d5-4e5e-a88b-59409d41956c
product-371fa0b53a1a13d2e83d09ce78bc4e2c50dc9024623035330ace70d28bbd88adLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:vth-542xh:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
72039fda-344d-4961-bb1b-e6f32eafd7c2
product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:vth-542xh_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.500.0000002.0.r.210715
- Match ID
6f1138dd-7149-4191-bf6b-5176b8ef3a07
product-5d68ae9f52c513c8491e04148705569729feb892262f989f6ea86e44523fe8a1Linked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:vto-65xxx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9438adc0-c8f4-48e1-a905-9914a3ae715e
product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:vto-65xxx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.300.0000004.0.r.210715
- Match ID
4ac98964-dbde-438c-a0e7-bf11d1bbc4b0
product-023119f2842657db700b35e9b3f8b273435b722d7ab35e733dc111bd29a22e8aLinked exactInspect raw assertion
cpe:2.3:h:dahuasecurity:vto-75x95x:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b205125d-5a33-49b0-a2ba-bd833d107924
product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976Linked exactInspect raw assertion
cpe:2.3:o:dahuasecurity:vto-75x95x_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.300.0000003.0.r.210714
- Match ID
a3fff94a-7f57-49d2-a6ba-5b58064c41c5
product-d63b8d1e22b55b2575c66022b19426f3648ce6610151c6b43698222df57571b1Linked exactInspect raw assertions
cpe:2.3:h:dahuasecurity:xvr-4x04:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97031a47-9275-45cd-afbb-a906a3a37d71
cpe:2.3:h:dahuasecurity:xvr-4x04:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97031a47-9275-45cd-afbb-a906a3a37d71
product-39164d767a090486d1b53509891097d249473546d98e9f247974a2453c4bf6c2Linked exactInspect raw assertions
cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5bfb4b89-fd66-4a9e-9163-8e27730012c8
cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 4.001.0000001.1.r.210709
- Match ID
c3d44b80-93ef-41ad-9bfd-b363cc8356cf
Affected-product evidence
Accepted scope and product mapping
18 canonical links · 1 source-reported links
vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-0206f23d31f14765aa36f952936cc31572c1df82c74e6ad6f8f2fbe4995a69b3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
38a073ad-9c8b-4d44-a52f-126c241d15a2vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
189b0bf9-a798-4357-9dc0-883158bf4306vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-19bee8739e50af92b11917581355f217835e86713f8f9bb8e176e6ac1eec71f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f9ebc22b-165f-4749-b2dd-44f0ffd330a0vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-2ba699b4fb7a01797ef7da980a8cb6a3038e24cd6e286fe449964d585caf5d40
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b109ee1e-294f-46e3-af6c-7b323eea2a74vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-39164d767a090486d1b53509891097d249473546d98e9f247974a2453c4bf6c2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4d1b3c90-9559-458d-8a7c-105e9709091bcb861d9c-e235-4b6e-b22d-e921cc30ba06vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3ad4ee9e65aead31f983c64d5d889cfa67b6a763564e56bde31ab01bb42cd5b2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bbbb0bcf-6954-4a0b-9243-3cb11ba0002bvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6c4f2d4eea70c68b7b05cdbfdbc39933eaac44650b805ee8dc5f6fe27a2c0e02
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
151445a3-9368-49fb-87a7-4a178e5b63abvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-73ffcbfbeee4f3ccc037a512655f7a2918183fb2556b36c6b539cb7853405b86
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12018602-98a1-4337-b59a-d9d7cf192412vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7d7db0eea822e6e5114d08258625df5cff36fc3cf5b01f86dffc10068a99a0a2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1a0c8883-bc99-43ae-a746-53e2f61d03e8vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f169cc0d-7138-44a1-9e31-4558ac099874vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-96d59685f21efd0d59e72371d31f8babf4ceba0808852d7c912d2b2bbf9b3ed8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ad5058dc-1edd-47ae-a0ec-f3ed5e8c7a0bvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d441e30b-7db7-41ba-9b58-35287d73c58fvendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a2ac98df-e4e9-4e5b-87ba-b88bcb72e963vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c4529ffa-5161-4da1-b585-670fa11bdb7avendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-c6fd4d04b4bfa52a47d8928f5c143ec7b165ee4133c59fd4ab9e0cfeb5b70aea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
52eda9d4-9354-425b-9975-36f738ff6c81vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-c8f856c2a909a349827cb8848b58fe6397c5f2756d99796025751d7395d981f0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9a98f688-4d97-470a-9939-8b418bfa1604vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b7d3ad4-a224-4768-9bf2-a03550a88464vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-f764750df2e09ee91f41a8fdd6426058f4e8ad2445c0a9566720246c5c831487
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9f9f285f-186c-4dcf-a2b5-fd8f4b8f6055Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7506e164-72f6-4ee0-a373-fbb412ab5d3cAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.