Record summary

CVE-2021-3152 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHHome Assistant HACS - Local File InclusionCVSS 7.5

Home Assistant before 2021.1.3 lacks a protection layer against directory-traversal attacks in custom integrations, letting attackers access arbitrary files, exploit requires attacker to deploy malicious custom integration.

Impact

Attackers can access sensitive files on the system, potentially leading to information disclosure or further system compromise.

Remediation

Update to version 2021.1.3 or later to include protection against directory traversal in custom integrations.

WeaknessesCWE-22
AuthorsDhiyaneshDk
Template tagscvecve2021hacshomeassistantlfi
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Shodan: title:"Home Assistant"
FOFA: title="Home Assistant"

Source: ProjectDiscovery

References

3