LiveActive security incident?Get immediate response
CVE Record

CVE-2020-36517: An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allo...

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Home Assistant OS and Home Assistant Supervised 2022.03 could leak clues about internal network resources through hardcoded DNS resolver behavior. The likely harm is exposure of internal hostnames or service names to a DNS operator, not direct system takeover based on the supplied evidence.

Executive priority

Treat this as a moderate confidentiality risk for environments using affected Home Assistant deployments. Prioritize validation in networks where internal device names, services, or locations are sensitive. No active exploitation or patch version is confirmed in the supplied evidence.

Technical view

CVE-2020-36517 describes an information leak caused by hardcoded DNS resolver configuration in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03. A DNS operator may learn about internal network resources from queries. The supplied sources do not include CVSS, CWE, confirmed fixed versions, or exploit details.

Likely exposure

Exposure is most relevant where Home Assistant OS or Home Assistant Supervised 2022.03 was deployed and DNS traffic could reach a resolver operator outside the trusted internal network. The bundle does not identify CPEs, all affected versions, or whether other Home Assistant deployment types are affected.

Exploitation context

The CVE is not listed as KEV in the supplied bundle, and no cited source states active exploitation. The scenario requires visibility into DNS queries handled by the configured resolver. This is primarily a confidentiality issue because DNS metadata can reveal internal resource names.

Researcher notes

The source bundle is thin: it provides the CVE description and references, but no CVSS vector, CWE, CPE, exploit evidence, or fixed release. Analysis should focus on DNS metadata exposure and resolver trust boundaries, not remote code execution or privilege escalation.

Mitigation direction

  • Check Home Assistant vendor guidance and linked plugin-dns issues for fixed versions.
  • Upgrade affected Home Assistant OS or Supervised installations when vendor guidance identifies a fix.
  • Ensure Home Assistant DNS queries use trusted resolvers appropriate for internal resources.
  • Avoid exposing sensitive internal hostnames through DNS forwarding where possible.
  • Monitor resolver logs for unexpected internal resource lookups.

Validation and detection

  • Inventory Home Assistant OS and Supervised installations, especially 2022.03 deployments.
  • Review DNS resolver settings and confirm queries use intended trusted resolvers.
  • Check whether internal hostnames appear in external or third-party resolver logs.
  • Review linked Home Assistant plugin-dns issues and pull requests for remediation status.
  • Confirm current deployments no longer rely on the vulnerable hardcoded resolver behavior.
Prepared
Confidence
medium
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-36517 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
16Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.