// For flags

CVE-2021-41104

web_server allows OTA update without checking user defined basic auth username & password

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.

ESPHome es un sistema para controlar el ESP8266/ESP32. Cualquiera que tenga web_server habilitado y la autenticación básica HTTP configurada en la versión 2021.9.1 o anterior, es vulnerable a un problema en el que "web_server" permite actualizaciones over-the-air (OTA) sin comprobar el nombre de usuario y la contraseña de autenticación básica definidos por el usuario. Este problema ha sido parcheado en la versión 2021.9.2. Como solución, se puede deshabilitar o eliminar "web_server"

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-09-15 CVE Reserved
  • 2021-09-28 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Esphome
Search vendor "Esphome"
Esphome Firmware
Search vendor "Esphome" for product "Esphome Firmware"
< 2021.9.2
Search vendor "Esphome" for product "Esphome Firmware" and version " < 2021.9.2"
-
Affected
in Espressif
Search vendor "Espressif"
Esp32
Search vendor "Espressif" for product "Esp32"
--
Safe
Esphome
Search vendor "Esphome"
Esphome Firmware
Search vendor "Esphome" for product "Esphome Firmware"
< 2021.9.2
Search vendor "Esphome" for product "Esphome Firmware" and version " < 2021.9.2"
-
Affected
in Espressif
Search vendor "Espressif"
Esp8266
Search vendor "Espressif" for product "Esp8266"
--
Safe