Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a critical vulnerability in Homer, an open-source telecom observability software, specifically affecting deployments using internal authentication before version 11.0.283. The issue stems from an automatically created default administrative account with a predictable password during initial setup, which lacks a mandatory change upon first login. This could allow unauthorized individuals direct administrative access to the system if they can reach the login endpoint.
- Default admin credentials grant full system access.
- Protects telecom observability systems from unauthorized control.
- Verify Homer deployment relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can gain full administrative control of a Homer deployment by accessing its login endpoint. This is possible because newly deployed instances of Homer, prior to a specific version, automatically create an administrative account with a default, hardcoded password. Once the attacker reaches the login page, they can use these credentials to access the system.
- Unauthenticated network access to login endpoint.
- Default `admin` account with `sipcapture` password.
- Full administrative access to the system.
Live Threat
Current exploitation, exposure, and threat context
When Homer is deployed with internal authentication and prior to version 11.0.283, an `admin` account with a default password exists. An attacker reaching the login endpoint could gain full administrative access, potentially affecting service behavior and sensitive information.
- Admin access to Homer is at risk.
- Attackers can reach the login endpoint.
- Compromise of observability data is possible.
Operational Fix
Recommended remediation, mitigation, and detection steps
For Homer deployments using internal authentication, platform or infrastructure teams should take the lead in addressing this vulnerability, as they typically manage observability tools. The first critical step is to identify all Homer instances, confirm their network accessibility and business criticality, and then locate the specific owner for each instance to plan remediation.
- Platform or infrastructure teams own resolution.
- Verify Homer instance reachability and criticality.
- Plan and execute updates during maintenance windows.