PT-2022-8972 · Nabu Casa · Home Assistant Supervised+1
Mtdcro
·
Published
2022-03-07
·
Updated
2022-03-14
·
CVE-2020-36517
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nabu Casa Home Assistant Operating System version 2022.03
Home Assistant Supervised version 2022.03
Description
An information leak in the affected systems allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
Recommendations
For Nabu Casa Home Assistant Operating System version 2022.03, consider updating the DNS resolver configuration to prevent information leaks.
For Home Assistant Supervised version 2022.03, update the DNS resolver configuration to mitigate the risk of internal network resource exposure.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Assistant Supervised
Nabu Casa Home Assistant Operating System