Authentication Bypass in Home Assistant Supervisor by Vendor Home Assistant
CVE-2023-27482

10CRITICAL

Key Information:

Vendor
CVE Published:
8 March 2023

What is CVE-2023-27482?

A significant security flaw has been identified in Home Assistant's Supervisor API, allowing unauthorized remote access due to an authentication bypass. This vulnerability affects all installations using Supervisor version 2023.01.1 or earlier. Affected users are strongly encouraged to upgrade to Supervisor version 2023.03.1 or later to mitigate this issue, as updates have been automatically rolled out to resolve the risk. Users unable to perform the upgrade should ensure that their Home Assistant instances are not exposed to the internet to reduce potential threats.

Affected Version(s)

core < 2023.3.2

supervisor < 2023.03.3

References

EPSS Score

87% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.