Vulnerability Description
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Homeautomation Project | Homeautomation | 3.3.2 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/290.htmlTechnical Description
- https://www.exploit-db.com/exploits/47807ExploitThird Party AdvisoryVDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5557.phpExploitThird Party Advisory
- https://cwe.mitre.org/data/definitions/290.htmlTechnical Description
- https://www.exploit-db.com/exploits/47807ExploitThird Party AdvisoryVDB Entry
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5557.phpExploitThird Party Advisory
FAQ
What is CVE-2020-22001?
CVE-2020-22001 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote con...
How severe is CVE-2020-22001?
CVE-2020-22001 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-22001?
Check the references section above for vendor advisories and patch information. Affected products include: Homeautomation Project Homeautomation.