S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-27482 Scanner

CVE-2023-27482 scanner - Authentication Bypass vulnerability in Home Assistant Core and Supervisor

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-27482
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
coreby home-assistant
< 2023.3.2
supervisorby home-assistant
< 2023.03.3
Updated Aug 22, 2026View on NVD →
Detail

Home Assistant Core and Supervisor are integral components of the popular open-source home automation system, Home Assistant. The Home Assistant Core is responsible for managing all aspects of home automation such as lighting, climate control, security systems, and more. It is essentially the brain of the home automation network. Meanwhile, the Supervisor is responsible for overseeing the management of operating system-level tasks and software updates for the Home Assistant Core.

The CVE-2023-27482 vulnerability detected in Home Assistant is a remotely exploitable vulnerability that bypasses authentication for accessing the Supervisor API through Home Assistant. This means that an attacker can gain access to the Supervisor API and execute any command they desire without requiring any type of authentication. This vulnerability only affects installations that use the Supervisor 2023.01.1 or older. Home Assistant Container and Home Assistant Core installations that are manually set up in a Python environment are not affected.

When exploited, the CVE-2023-27482 vulnerability can lead to a complete takeover of the Home Assistant instance. Attackers can execute any command via the Supervisor API, making them capable of taking full control of any connected smart devices within the home automation network. This puts users' privacy and security at risk and could lead to significant damage if not promptly addressed.

Security is important, and it is vital to keep all digital assets secure. With the pro features of s4e.io, readers can easily and quickly learn about vulnerabilities in their digital assets. The pro features of s4e.io provide detailed information on vulnerabilities, along with actionable insights to mitigate them. By leveraging the power of s4e.io, users can stay ahead of threats and protect their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Upgrade to at least Home Assistant Core 2023.3.0 or later, which includes mitigation for this vulnerability.
  • Make sure that the Home Assistant Supervisor and Core applications are always up to date with the latest releases.
  • Do not expose Home Assistant instances to the internet.
  • Use a firewall to restrict access to the Home Assistant instance from external networks.
  • Disable Supervisor API access altogether if it is not necessary for your use case.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.