CVE-2021-41104
Summary
| CVE | CVE-2021-41104 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-28 16:15:00 UTC |
| Updated | 2021-10-07 14:13:00 UTC |
| Description | ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulnerable to an issue in which `web_server` allows over-the-air (OTA) updates without checking user defined basic auth username & password. This issue is patched in version 2021.9.2. As a workaround, one may disable or remove `web_server`. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| web_server allows OTA update without checking user defined basic auth username & password · Advisory · esphome/esphome · GitHub | CONFIRM | github.com | |
| Fix lint issues in web_server_base by jesserockz · Pull Request #2409 · esphome/esphome · GitHub | MISC | github.com | |
| Release 2021.9.2 · esphome/esphome · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980635 Python (pip) Security Update for esphome (GHSA-48mj-p7x2-5jfm)