PT-2020-5629 · Microsoft+12 · Xbox One+13
Published
2014-02-06
·
Updated
2024-06-15
·
CVE-2020-12695
CVSS v2.0
7.8
High
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Open Connectivity Foundation UPnP specification versions prior to 2020-04-17
4thline cling versions 2.0.0 through 2.1.2
Description
The issue is related to the UPnP protocol, which allows remote attackers to cause a denial of service via an unchecked
CALLBACK parameter in the request header. This vulnerability can be exploited to extract data from networks, scan ports of computers on the internal network, and amplify DDoS attacks using millions of connected UPnP devices, such as cable modems, home routers, game consoles, IP cameras, TV set-top boxes, media centers, and printers. The estimated number of potentially affected devices worldwide is not specified, but it is known to affect a wide range of devices, including PC with Windows 10, Xbox One, modems and routers from different manufacturers, smart TVs, and "smart home" devices.Recommendations
For Open Connectivity Foundation UPnP specification versions prior to 2020-04-17: Consider disabling the UPnP protocol until a patch is available.
For 4thline cling versions 2.0.0 through 2.1.2: As 4thline cling is no longer supported by the maintainers, consider upgrading to a supported alternative or disabling the vulnerable
CALLBACK parameter in the request header.
As a temporary workaround, consider restricting access to the UPnP protocol to minimize the risk of exploitation. Additionally, consider closing UPnP ports to prevent potential attacks.Exploit
Fix
SSRF
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Open Connectivity Foundation Upnp
Red Hat
Rocky Linux
Suse
Ubuntu
Windows 10
Xbox One
Cling