HIGH · 7.5

CVE-2020-12695

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualifi...

Vulnerability Description

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
UiUnifi Controller-
W1.FiHostapd< 2.0.0
AsusRt-N11-
BroadcomAdsl-
CanonSelphy Cp1200-
CiscoWap131-
CiscoWap150-
CiscoWap351-
DlinkDvg-N5412Sp-
DellB1165Nfw-
EpsonEp-101-
EpsonEw-M970A3T-
EpsonM571T-
EpsonXp-100-
EpsonXp-2101-
EpsonXp-2105-
EpsonXp-241-
EpsonXp-320-
EpsonXp-330-
EpsonXp-340-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12695?

CVE-2020-12695 is a vulnerability with a CVSS score of 7.5 (HIGH). The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualifi...

How severe is CVE-2020-12695?

CVE-2020-12695 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12695?

Check the references section above for vendor advisories and patch information. Affected products include: Ui Unifi Controller, W1.Fi Hostapd, Asus Rt-N11, Broadcom Adsl, Canon Selphy Cp1200.