// For flags

CVE-2021-45099

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a defense-in-depth measure against complex social engineering situations

**EN DISPUTA** El servicio addon.stdin en addon-ssh (también se conoce como Home Assistant Community Add-on: SSH & Web Terminal) versiones anteriores a 10.0.0, presenta una superficie de ataque que requiere ingeniería social. NOTA: el proveedor no está de acuerdo en que esto sea una vulnerabilidad; sin embargo, addon.stdin fue eliminado como una medida de defensa en profundidad contra situaciones complejas de ingeniería social

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2021-12-16 CVE Reserved
  • 2021-12-16 CVE Published
  • 2024-08-31 EPSS Updated
  • 2024-11-18 CVE Updated
  • 2024-11-18 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ssh \& Web Terminal Project
Search vendor "Ssh \& Web Terminal Project"
Ssh \& Web Terminal
Search vendor "Ssh \& Web Terminal Project" for product "Ssh \& Web Terminal"
< 10.0.0
Search vendor "Ssh \& Web Terminal Project" for product "Ssh \& Web Terminal" and version " < 10.0.0"
home_assistant
Affected