CVE-2023-41894
Local-only webhooks externally accessible via SniTun in Home Assistant Core
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from the local network. This issue is facilitated by the SniTun proxy, which sets the source address to 127.0.0.1 on all requests sent to the public URL and forwarded to the local Home Assistant. This issue has been addressed in version 2023.9.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Home Assistant es una domótica de código abierto. La evaluación verificó que los webhooks disponibles en el componente webhook se pueden activar a través de la URL `*.ui.nabu.casa` sin autenticación, incluso cuando el webhook está marcado como Solo accesible desde la red local. Este problema se ve facilitado por el proxy SniTun, que establece la dirección de origen en 127.0.0.1 en todas las solicitudes enviadas a la URL pública y reenviadas al Home Assistant local. Este problema se solucionó en la versión 2023.9.0 y se recomienda a todos los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-04 CVE Reserved
- 2023-10-19 CVE Published
- 2024-09-12 CVE Updated
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-669: Incorrect Resource Transfer Between Spheres
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Home-assistant Search vendor "Home-assistant" | Home-assistant Search vendor "Home-assistant" for product "Home-assistant" | < 2023.9.0 Search vendor "Home-assistant" for product "Home-assistant" and version " < 2023.9.0" | - |
Affected
|