ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-563: (Pwn2Own) Home Assistant Green Simple Service Discovery Protocol Server-Side Request Forgery Vulnerability

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

ZDI disclosed a Pwn2Own SSRF flaw (CVSS 5.4) in Home Assistant Green's SSDP server, letting unauthenticated network-adjacent attackers trigger arbitrary server-side requests.

The Zero Day Initiative published ZDI-26-563 for a server-side request forgery in the Simple Service Discovery Protocol server on Home Assistant Green. The bug was demonstrated at Pwn2Own and allows network-adjacent, unauthenticated attackers to initiate arbitrary server-side requests on affected installations. ZDI rated the issue CVSS 5.4.

  • Network-adjacent attackers can trigger arbitrary server-side requests without authentication.
  • Flaw was demonstrated at Pwn2Own; ZDI assigned CVSS 5.4.
Full article

This vulnerability allows network-adjacent attackers to initiate arbitrary server-side requests on affected installations of Home Assistant Green. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.4.

This source does not provide full text. Read it at zerodayinitiative.com.