PT-2024-30935 · Pi-Hole · Pi-Hole

Kiyell

·

Published

2024-08-18

·

Updated

2024-10-29

·

CVE-2024-44069

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pi-hole versions prior to 6
Description The issue allows unauthenticated calls to "admin/api.php?setTempUnit=" to change the temperature units of the web dashboard. The supplier reportedly does not consider this a security issue, but the motivation for allowing arbitrary persons to change the value, which can be seen by the device owner, is unclear.
Recommendations For versions prior to 6, update to version 6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "admin/api.php?setTempUnit=" endpoint until a patch is available.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-44069

Affected Products

Pi-Hole