← Vulnerability feed

Vulnerability record · CVE-2020-36517 · published 10 March 2022

CVE-2020-36517: Home-assistant observable discrepancy vulnerability

Home Assistant · Home Assistant

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.

7.5 CVSS 3.1 High EPSS 2.9% · top 13.6% CWE-203 · Observable discrepancy
7.5CVSS 3.1 base score, v2 5.0
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 22 tagged exploit
17 Jun 2026Last modified by NVD

Description

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://community.home-assistant.io/t/ha-os-dns-setting-configuration-not-respected/356572 ExploitIssue TrackingVendor Advisory
https://github.com/home-assistant/plugin-dns/issues/17 Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/20 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/22 Issue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/50 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/51 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/53 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/54 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/6 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/64 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/70 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/55 ExploitPatchThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/56 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/58 PatchThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/59 Issue TrackingPatchThird Party Advisory
https://community.home-assistant.io/t/ha-os-dns-setting-configuration-not-respected/356572 ExploitIssue TrackingVendor Advisory
https://github.com/home-assistant/plugin-dns/issues/17 Third Party Advisory
https://github.com/home-assistant/plugin-dns/issues/20 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/22 Issue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/50 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/51 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/53 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/54 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/6 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/64 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/issues/70 ExploitThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/55 ExploitPatchThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/56 ExploitIssue TrackingThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/58 PatchThird Party Advisory
https://github.com/home-assistant/plugin-dns/pull/59 Issue TrackingPatchThird Party Advisory

Track CVE-2020-36517 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-27482Home Assistant Supervisor authentication bypass via APIHome Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication an…EPSS 72%analysed9.6CVE-2023-41895Home-assistant cross-site scripting vulnerabilityHome assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in…EPSS 0.67%9.6CVE-2023-41897Home-assistant clickjacking vulnerabilityHome assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header,…EPSS 0.95%9.0CVE-2023-41896Home-assistant insufficient verification of data authenticity vulnerabilityHome assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`,…EPSS 0.27%7.6CVE-2026-54317Home-assistant information exposure vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…EPSS 0.31%7.5CVE-2018-21019Home-assistant information exposure vulnerabilityHome Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log…EPSS 1.7%7.3CVE-2026-33045Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…EPSS 0.25%7.3CVE-2026-33044Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2020-36517), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.