A security vulnerability affecting specific software versions has been identified in the devices listed below. We recommend checking your device's software version, reviewing the information and recommended actions below, and consulting in our guide CCTV Systems Security.


Security Advisory Details

Advisory Identifier SA-20260921-1
CVE Vulnerability CVE-2021-33045 open_in_new
Vulnerability Nature / Description Obejście uwierzytelniania związane z nieprawidłową walidacją parametrów klienta podczas procesu logowania. / Authentication bypass related to improper validation of client parameters during the login process.

Devices affected by the vulnerability

Refers to: 05/2020 (and earlier / previously released)

Device models:

BCS-BIP7201-Ai, BCS-BIP7401-Ai, BCS-BIP7501-Ai, BCS-BIP91200-Ai, BCS-DMIP1201IR-E-V, BCS-DMIP1401IR-E-V, BCS-DMIP2201IR-Ai, BCS-DMIP2201IR-E-Ai, BCS-DMIP2201IR-V-Ai, BCS-DMIP2201IR-V-E-Ai, BCS-DMIP2201IR-V-V, BCS-DMIP2401IR-Ai, BCS-DMIP2401IR-V-V, BCS-DMIP2501IR-Ai, BCS-DMIP2501IR-E-Ai, BCS-DMIP2501IR-V-Ai, BCS-DMIP2501IR-V-E-Ai, BCS-DMIP2801IR-E-Ai, BCS-DMIP2801IR-V-E-Ai, BCS-DMIP3201IR-Ai, BCS-DMIP3201IR-E-Ai, BCS-DMIP3201IR-E-V, BCS-DMIP3201IR-V-E-Ai, BCS-DMIP3201IR-V-V, BCS-DMIP3401IR-Ai, BCS-DMIP3401IR-E-V, BCS-DMIP3401IR-V-V, BCS-DMIP3501IR-Ai, BCS-DMIP3501IR-E-Ai, BCS-DMIP3501IR-V-E-Ai, BCS-DMIP3801IR-E-Ai, BCS-DMIP3801IR-V-E-Ai, BCS-DMIP5201IR-Ai, BCS-DMIP5401IR-Ai, BCS-DMIP5501IR-Ai, BCS-DMMIP1201IR-E-Ai, BCS-DMMIP1501IR-E-Ai, BCS-L-DIP44VWR4, BCS-L-EIP14FR3, BCS-L-EIP44VWR5, BCS-L-EIP52FCL3-AI1, BCS-L-EIP55FCL3-Ai1, BCS-L-EIP58FCL3-AI1, BCS-L-TIP14FR3, BCS-L-TIP44VWR5, BCS-L-TIP52FCL4-AI1, BCS-L-TIP55FCL4-Ai1, BCS-L-TIP58FCL4-AI1, BCS-TIP3201IR-E-V, BCS-TIP3401IR-E-V, BCS-TIP4201IR-Ai, BCS-TIP4401IR-Ai, BCS-TIP4501IR-Ai, BCS-TIP4501IR-E-Ai, BCS-TIP4801IR-E-Ai, BCS-TIP5201IR-Ai, BCS-TIP5201IR-V-E-Ai, BCS-TIP5201IR-V-VI, BCS-TIP5401IR-Ai, BCS-TIP5401IR-V-VI, BCS-TIP5501IR-Ai, BCS-TIP5501IR-V-E-Ai, BCS-TIP5801IR-V-E-Ai, BCS-TIP8201IR-Ai, BCS-TIP8401IR-Ai, BCS-TIP8501IR-Ai, BCS-TIP91200IR-Ai
Refers to: 12/2019 (and earlier / previously released)

Device models:

BCS-L-SXVR0401-4KE-III, BCS-L-XVR0401-4KE-IV, BCS-L-XVR0401-VI, BCS-L-XVR0801-V, BCS-XVR0401-V, BCS-XVR0401E-IV, BCS-XVR0401E-V, BCS-XVR04014KE-E-II, BCS-XVR04014KE-III, BCS-XVR0801-IV, BCS-XVR0801E-III, BCS-XVR08014KE-III, BCS-XVR08024KE-III, BCS-XVR1601-IV, BCS-XVR1602-IV, BCS-XVR3202-IV, BCS-XVR3204-III, BCS-XVR3204-IV, BCS-XVR16014KE-III, BCS-XVR16024KE-III, BCS-XVR16044KE-III, BCS-XVR32044KE-III

info Recommended Action

We recommend updating the device to the latest available software version for the specific model and hardware revision. Before updating, please verify the software's compatibility with the device.

Additional safety recommendations
To reduce the risk of unauthorized access to the device, we recommend:

  • using strong and unique passwords
  • avoiding direct sharing of the device on the Internet
  • disabling unused services and protocols
  • regularly checking for software updates

More information: CCTV Systems Security Guide

Device Identification and Firmware Download

Prepare the device's serial number (SN) ready to check device information and available software.

security
Want to stay informed about future security updates or report a vulnerability? Go to Product Safety - Vulnerability Reporting, Subscription to Security Bulletins and Advisories

Many years of experience supported by knowledge and commitment

Help and technical support

Efficient service of devices