Evidence dossier

CVE-2021-33045

The identity authentication bypass vulnerability found in some Dahua products during the login process.

Exploited in the wild (CISA KEV since Aug 21, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 99.6% exploit likelihood as of Aug 18, 2026.

92.092.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

State
PUBLISHED
Published
Sep 15, 2021
Updated
Jan 12, 2026
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    dahua

    Record text: The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

    Inspect raw assertion
    Field
    container
    Value
    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Dahua IP Camera Authentication Bypass Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Dahua IP Camera Authentication Bypass Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.56% probability · 99.94th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.995560000000; percentile 0.999440000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Aug 21, 2024 · first observed Jul 19, 2026

Exploit likelihood99.56%

FIRST EPSS · score date Aug 18, 2026 · 99.9th percentile · first observed Aug 18, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
dahuaOriginal assertion
Record text

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

Inspect raw assertion
Field
container
Value
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Dahua IP Camera Authentication Bypass Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Dahua IP Camera Authentication Bypass Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.56% probability · 99.94th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.995560000000; percentile 0.999440000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
38Underlying assertions
36Canonical products
19Target assertions
19Constraint assertions

Grouped from 38 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

37 scope groups

dahua · source assertedn/aSome Dahua IP Camera, Video Intercom, NVR, XVR devicesDirect source scope
Affected: Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019.
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Dahua IP Camera devices IPC-HX3XXX, IPC-HX5XXX, and IPC-HUM7XXX Buildtime before May, 2020, Video Intercom devices VTO75X95X, VTO65XXX, and VTH542XH, NVR devices NVR1XXX, NVR2XXX, NVR5XXX, and NVR6XX, XVR devices XVR4xxx, XVR5xxx, and XVR7xxx Buildtime before December, 2019."}]
NVD CPE · HARDWAREdahuasecurityipc-hum7xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-0b324caf3dae3219702267c9a2a87caddf5853fa49b32717441fbaea0bfdf15aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hum7xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ae9acb0-4cb3-4cf5-a007-15ee977d782e
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hum7xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.820.0000000.5.r.210705)Canonical identity product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22efLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hum7xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.820.0000000.5.r.210705
    Match ID
    c0356805-3ecf-4c6f-b2bf-95d507736c44
NVD CPE · HARDWAREdahuasecurityipc-hx3xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-98608b4baf28cb9e54d1efb8f911625999a6adf89f0ba5c1faf03e3ce6bc1bb9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hx3xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8936a118-4ab5-4b09-a9fd-e624a68315bd
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hx3xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.800.0000000.29.r.210630)Canonical identity product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hx3xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.800.0000000.29.r.210630
    Match ID
    e0d17050-41ca-4808-8ed3-f332fd00b551
NVD CPE · HARDWAREdahuasecurityipc-hx5xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3962717b13ae9e96041309f6500006c82125a6268fbc1202ac3b39a45a1f1227Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:ipc-hx5xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2838bda-97ff-498e-bc81-955d31b9227a
NVD CPE · OPERATING SYSTEMdahuasecurityipc-hx5xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 2.820.0000000.5.r.210705)Canonical identity product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:ipc-hx5xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.820.0000000.5.r.210705
    Match ID
    3f20dc69-b735-4547-826d-e4c42a39fe82
NVD CPE · HARDWAREdahuasecuritynvr-1xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-528fb3e4e84a7f68366acd20796cf90c1d5508f9807a92aa44e66c794261fdfeLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:nvr-1xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7780d1be-abe0-4890-b493-36fa0a4b3266
NVD CPE · OPERATING SYSTEMdahuasecuritynvr-1xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.001.0000005.1.r.210709)Canonical identity product-6c4f2d4eea70c68b7b05cdbfdbc39933eaac44650b805ee8dc5f6fe27a2c0e02Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:nvr-1xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000005.1.r.210709
    Match ID
    fa1c3935-c83b-4a1a-beee-ef93f7722972
NVD CPE · HARDWAREdahuasecuritynvr-2xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-cefaf7c4ddce9bd8c898f71e21f089b7774fc4d3a8b843519cb36d440bd743bcLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:nvr-2xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    89e3f7b3-3c51-49c1-baec-da4235d5a06d
NVD CPE · OPERATING SYSTEMdahuasecuritynvr-2xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.001.0000000.1.r.210710)Canonical identity product-c8f856c2a909a349827cb8848b58fe6397c5f2756d99796025751d7395d981f0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:nvr-2xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000000.1.r.210710
    Match ID
    795ef8b2-5e6d-46eb-9f66-85f2c71b2619
NVD CPE · HARDWAREdahuasecuritynvr-4xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-26b2d11926ebea5922f643367cecd76fd701da450adffead82c7c1c782895723Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:nvr-4xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58ecdc49-09d4-4e62-ac11-e3c52c656a9d
NVD CPE · OPERATING SYSTEMdahuasecuritynvr-4xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.001.0000005.1.r.210713)Canonical identity product-7d7db0eea822e6e5114d08258625df5cff36fc3cf5b01f86dffc10068a99a0a2Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:nvr-4xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000005.1.r.210713
    Match ID
    1386662b-c3de-467a-8f41-f18bde7b9726
NVD CPE · HARDWAREdahuasecuritynvr-5xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-8f92c1e4b7d1edbe5ba2b824ca7a63665261da226c2463e3a382555d2105b573Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:nvr-5xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de621958-8ae2-44e0-9e41-94bc964cdf57
NVD CPE · OPERATING SYSTEMdahuasecuritynvr-5xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.001.0000000.0.r.210710)Canonical identity product-0206f23d31f14765aa36f952936cc31572c1df82c74e6ad6f8f2fbe4995a69b3Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:nvr-5xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000000.0.r.210710
    Match ID
    06a6b28a-2e0d-4e45-904a-66fee5d85262
NVD CPE · HARDWAREdahuasecuritynvr-6xxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3c9e928c71879e62087b4f519c51f51a7399d7e2786a6daf0547532bfe132a91Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:nvr-6xx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9eeac798-870e-4de6-b7db-44faf5360ce5
NVD CPE · OPERATING SYSTEMdahuasecuritynvr-6xx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.001.0000001.1.r.210716)Canonical identity product-c6fd4d04b4bfa52a47d8928f5c143ec7b165ee4133c59fd4ab9e0cfeb5b70aeaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:nvr-6xx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000001.1.r.210716
    Match ID
    90d5a1b3-88d5-4e5e-a88b-59409d41956c
NVD CPE · HARDWAREdahuasecurityvth-542xhEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-371fa0b53a1a13d2e83d09ce78bc4e2c50dc9024623035330ace70d28bbd88adLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:vth-542xh:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    72039fda-344d-4961-bb1b-e6f32eafd7c2
NVD CPE · OPERATING SYSTEMdahuasecurityvth-542xh_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.500.0000002.0.r.210715)Canonical identity product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:vth-542xh_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.500.0000002.0.r.210715
    Match ID
    6f1138dd-7149-4191-bf6b-5176b8ef3a07
NVD CPE · HARDWAREdahuasecurityvto-65xxxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5d68ae9f52c513c8491e04148705569729feb892262f989f6ea86e44523fe8a1Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:vto-65xxx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9438adc0-c8f4-48e1-a905-9914a3ae715e
NVD CPE · OPERATING SYSTEMdahuasecurityvto-65xxx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.300.0000004.0.r.210715)Canonical identity product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:vto-65xxx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.300.0000004.0.r.210715
    Match ID
    4ac98964-dbde-438c-a0e7-bf11d1bbc4b0
NVD CPE · HARDWAREdahuasecurityvto-75x95xEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-023119f2842657db700b35e9b3f8b273435b722d7ab35e733dc111bd29a22e8aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:dahuasecurity:vto-75x95x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b205125d-5a33-49b0-a2ba-bd833d107924
NVD CPE · OPERATING SYSTEMdahuasecurityvto-75x95x_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 4.300.0000003.0.r.210714)Canonical identity product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:dahuasecurity:vto-75x95x_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.300.0000003.0.r.210714
    Match ID
    a3fff94a-7f57-49d2-a6ba-5b58064c41c5
NVD CPE · HARDWAREdahuasecurityxvr-4x04Environmental constraint · 2 assertions
Version not applicableCanonical identity product-d63b8d1e22b55b2575c66022b19426f3648ce6610151c6b43698222df57571b1Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:dahuasecurity:xvr-4x04:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97031a47-9275-45cd-afbb-a906a3a37d71
  2. cpe:2.3:h:dahuasecurity:xvr-4x04:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97031a47-9275-45cd-afbb-a906a3a37d71
NVD CPE · OPERATING SYSTEMdahuasecurityxvr-4x04_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (< 4.001.0000001.1.r.210709); Version not applicableCanonical identity product-39164d767a090486d1b53509891097d249473546d98e9f247974a2453c4bf6c2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5bfb4b89-fd66-4a9e-9163-8e27730012c8
  2. cpe:2.3:o:dahuasecurity:xvr-4x04_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 4.001.0000001.1.r.210709
    Match ID
    c3d44b80-93ef-41ad-9bfd-b363cc8356cf

Affected-product evidence

Accepted scope and product mapping

18 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-0206f23d31f14765aa36f952936cc31572c1df82c74e6ad6f8f2fbe4995a69b3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
38a073ad-9c8b-4d44-a52f-126c241d15a2
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-132d368b77e9e9aed70d0ada257a4e0523b22c2c8aff1ac3ff5f55c43c8af630

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
189b0bf9-a798-4357-9dc0-883158bf4306
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-19bee8739e50af92b11917581355f217835e86713f8f9bb8e176e6ac1eec71f4

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f9ebc22b-165f-4749-b2dd-44f0ffd330a0
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-2ba699b4fb7a01797ef7da980a8cb6a3038e24cd6e286fe449964d585caf5d40

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b109ee1e-294f-46e3-af6c-7b323eea2a74
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-39164d767a090486d1b53509891097d249473546d98e9f247974a2453c4bf6c2

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4d1b3c90-9559-458d-8a7c-105e9709091bcb861d9c-e235-4b6e-b22d-e921cc30ba06
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-3ad4ee9e65aead31f983c64d5d889cfa67b6a763564e56bde31ab01bb42cd5b2

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bbbb0bcf-6954-4a0b-9243-3cb11ba0002b
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-6c4f2d4eea70c68b7b05cdbfdbc39933eaac44650b805ee8dc5f6fe27a2c0e02

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
151445a3-9368-49fb-87a7-4a178e5b63ab
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-73ffcbfbeee4f3ccc037a512655f7a2918183fb2556b36c6b539cb7853405b86

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
12018602-98a1-4337-b59a-d9d7cf192412
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7d7db0eea822e6e5114d08258625df5cff36fc3cf5b01f86dffc10068a99a0a2

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1a0c8883-bc99-43ae-a746-53e2f61d03e8
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-7ff9b27c75fec01b1a1d5a32c705f6a613ad86b2cb4382785d87f9525d2f22ef

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f169cc0d-7138-44a1-9e31-4558ac099874
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-96d59685f21efd0d59e72371d31f8babf4ceba0808852d7c912d2b2bbf9b3ed8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ad5058dc-1edd-47ae-a0ec-f3ed5e8c7a0b
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-979c6fa8d730283e918191f1b2d24275d8a116c546a89ab0cdbe20c68ff072b6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d441e30b-7db7-41ba-9b58-35287d73c58f
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-b4e3c3feec4218705fb7b79ac2ab928881cb9f29cbb13b6f4810ea5789e3a02f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a2ac98df-e4e9-4e5b-87ba-b88bcb72e963
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-baa5f3c6c494095d0f792ecfee360228a49c8ca1f5884fae14f6d4e6067bbc48

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c4529ffa-5161-4da1-b585-670fa11bdb7a
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-c6fd4d04b4bfa52a47d8928f5c143ec7b165ee4133c59fd4ab9e0cfeb5b70aea

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
52eda9d4-9354-425b-9975-36f738ff6c81
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-c8f856c2a909a349827cb8848b58fe6397c5f2756d99796025751d7395d981f0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9a98f688-4d97-470a-9939-8b418bfa1604
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-e018cc863ef0a2660861a44663986e2f7f44c756b40d5ae6dba5f0e8ad0b6976

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5b7d3ad4-a224-4768-9bf2-a03550a88464
Mapping establishedEvidence supported

vendor-79b5861c2f8bedf4ba293b0a2797f8b6a6f6f3a2344f997545e32c95b82e635a · product-f764750df2e09ee91f41a8fdd6426058f4e8ad2445c0a9566720246c5c831487

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9f9f285f-186c-4dcf-a2b5-fd8f4b8f6055
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7506e164-72f6-4ee0-a373-fbb412ab5d3c

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.