CVE-2021-41104
web_server allows OTA update without checking user defined basic auth username & password
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`.
ESPHome es un sistema para controlar el ESP8266/ESP32. Cualquiera que tenga web_server habilitado y la autenticación básica HTTP configurada en la versión 2021.9.1 o anterior, es vulnerable a un problema en el que "web_server" permite actualizaciones over-the-air (OTA) sin comprobar el nombre de usuario y la contraseña de autenticación básica definidos por el usuario. Este problema ha sido parcheado en la versión 2021.9.2. Como solución, se puede deshabilitar o eliminar "web_server"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-15 CVE Reserved
- 2021-09-28 CVE Published
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/esphome/esphome/releases/tag/2021.9.2 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Esphome Search vendor "Esphome" | Esphome Firmware Search vendor "Esphome" for product "Esphome Firmware" | < 2021.9.2 Search vendor "Esphome" for product "Esphome Firmware" and version " < 2021.9.2" | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp32 Search vendor "Espressif" for product "Esp32" | - | - |
Safe
|
Esphome Search vendor "Esphome" | Esphome Firmware Search vendor "Esphome" for product "Esphome Firmware" | < 2021.9.2 Search vendor "Esphome" for product "Esphome Firmware" and version " < 2021.9.2" | - |
Affected
| in | Espressif Search vendor "Espressif" | Esp8266 Search vendor "Espressif" for product "Esp8266" | - | - |
Safe
|