imPC@ndo IT

Tracker / CVE-2020-12695

CVE-2020-12695

High 7.5

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Affected products and versions

asus rt-n11
broadcom adsl
canon selphy_cp1200
canonical ubuntu_linux
cisco wap131
cisco wap150
cisco wap351
debian debian_linux
dell b1165nfw
dlink dvg-n5412sp
epson ep-101
epson ew-m970a3t
epson m571t
epson xp-100
epson xp-2101
epson xp-2105
epson xp-241
epson xp-320
epson xp-330
epson xp-340
epson xp-4100
epson xp-4105
epson xp-440
epson xp-620
epson xp-630
epson xp-702
epson xp-8500
epson xp-8600
epson xp-960
epson xp-970
fedoraproject fedora
hp 5020_z4a69a
hp 5030_m2u92b
hp 5030_z4a70a
hp 5034_z4a74a
hp 5660_f8b04a
hp deskjet_ink_advantage_3456_a9t84c
hp deskjet_ink_advantage_3545_a9t81a
hp deskjet_ink_advantage_3545_a9t81c
hp deskjet_ink_advantage_3545_a9t83b
hp deskjet_ink_advantage_3546_a9t82a
hp deskjet_ink_advantage_3548_a9t81b
hp deskjet_ink_advantage_4515
hp deskjet_ink_advantage_4518
hp deskjet_ink_advantage_4535_f0v64a
hp deskjet_ink_advantage_4535_f0v64b
hp deskjet_ink_advantage_4535_f0v64c
hp deskjet_ink_advantage_4536_f0v65a
hp deskjet_ink_advantage_4538_f0v66b
hp deskjet_ink_advantage_4675_f1h97a
hp deskjet_ink_advantage_4675_f1h97b
hp deskjet_ink_advantage_4675_f1h97c
hp deskjet_ink_advantage_4676_f1h98a
hp deskjet_ink_advantage_4678_f1h99b
hp deskjet_ink_advantage_5575_g0v48b
hp deskjet_ink_advantage_5575_g0v48c
hp envy_100_cn517a
hp envy_100_cn517b
hp envy_100_cn517c
hp envy_100_cn518a

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References