PT-2022-8972 · Nabu Casa · Home Assistant Supervised+1

Mtdcro

·

Published

2022-03-07

·

Updated

2022-03-14

·

CVE-2020-36517

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nabu Casa Home Assistant Operating System version 2022.03 Home Assistant Supervised version 2022.03
Description An information leak in the affected systems allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
Recommendations For Nabu Casa Home Assistant Operating System version 2022.03, consider updating the DNS resolver configuration to prevent information leaks. For Home Assistant Supervised version 2022.03, update the DNS resolver configuration to mitigate the risk of internal network resource exposure.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36517

Affected Products

Home Assistant Supervised
Nabu Casa Home Assistant Operating System