CVE-2020-36517: High severity skydrive assistant vulnerability
Published Mar 7, 2022
·Updated
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
Affected Software
1 affected component
home-assistant home-assistant=2022.03
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 7, 2022
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this information leak vulnerability?
The vulnerability ID is CVE-2020-36517.
2
What is the severity of CVE-2020-36517?
The severity of CVE-2020-36517 is high.
3
How does the vulnerability in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 occur?
The vulnerability occurs due to an information leak that allows a DNS operator to gain knowledge about internal network resources.
4
Which software versions are affected by CVE-2020-36517?
The affected software version is Home Assistant 2022.03.
5
Are there any fixes or patches available for this vulnerability?
The references provided may contain information about available fixes or patches for CVE-2020-36517.