Vulnerability Description
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Unifi Controller | - |
| W1.Fi | Hostapd | < 2.0.0 |
| Asus | Rt-N11 | - |
| Broadcom | Adsl | - |
| Canon | Selphy Cp1200 | - |
| Cisco | Wap131 | - |
| Cisco | Wap150 | - |
| Cisco | Wap351 | - |
| Dlink | Dvg-N5412Sp | - |
| Dell | B1165Nfw | - |
| Epson | Ep-101 | - |
| Epson | Ew-M970A3T | - |
| Epson | M571T | - |
| Epson | Xp-100 | - |
| Epson | Xp-2101 | - |
| Epson | Xp-2105 | - |
| Epson | Xp-241 | - |
| Epson | Xp-320 | - |
| Epson | Xp-330 | - |
| Epson | Xp-340 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158051/CallStranger-UPnP-Vulnerability-ChecThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2020/06/08/2Mailing ListThird Party Advisory
- https://corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerabilThird Party Advisory
- https://github.com/corelight/callstranger-detectorThird Party Advisory
- https://github.com/yunuscadirci/CallStrangerThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00011.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00013.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/12/msg00017.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproMailing ListThird Party Advisory
- https://usn.ubuntu.com/4494-1/Third Party Advisory
- https://www.callstranger.comBroken Link
- https://www.debian.org/security/2020/dsa-4806Third Party Advisory
- https://www.debian.org/security/2021/dsa-4898Third Party Advisory
FAQ
What is CVE-2020-12695?
CVE-2020-12695 is a vulnerability with a CVSS score of 7.5 (HIGH). The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualifi...
How severe is CVE-2020-12695?
CVE-2020-12695 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12695?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Controller, W1.Fi Hostapd, Asus Rt-N11, Broadcom Adsl, Canon Selphy Cp1200.