PT-2020-5629 · Microsoft+12 · Xbox One+13

Published

2014-02-06

·

Updated

2024-06-15

·

CVE-2020-12695

CVSS v2.0

7.8

High

VectorAV:N/AC:M/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Open Connectivity Foundation UPnP specification versions prior to 2020-04-17 4thline cling versions 2.0.0 through 2.1.2
Description The issue is related to the UPnP protocol, which allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header. This vulnerability can be exploited to extract data from networks, scan ports of computers on the internal network, and amplify DDoS attacks using millions of connected UPnP devices, such as cable modems, home routers, game consoles, IP cameras, TV set-top boxes, media centers, and printers. The estimated number of potentially affected devices worldwide is not specified, but it is known to affect a wide range of devices, including PC with Windows 10, Xbox One, modems and routers from different manufacturers, smart TVs, and "smart home" devices.
Recommendations For Open Connectivity Foundation UPnP specification versions prior to 2020-04-17: Consider disabling the UPnP protocol until a patch is available. For 4thline cling versions 2.0.0 through 2.1.2: As 4thline cling is no longer supported by the maintainers, consider upgrading to a supported alternative or disabling the vulnerable CALLBACK parameter in the request header. As a temporary workaround, consider restricting access to the UPnP protocol to minimize the risk of exploitation. Additionally, consider closing UPnP ports to prevent potential attacks.

Exploit

Fix

SSRF

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1789
ALT-PU-2014-1157
ALT-PU-2020-2224
BDU:2021-01329
CESA-2021_1789
CVE-2020-12695
DLA-2315-1
DLA-2318-1
DLA-2489-1
DSA-4806-1
DSA-4806-2
DSA-4898-1
GHSA-C438-6F6R-PG8W
MGASA-2020-0304
MGASA-2020-0483
OESA-2022-1768
OPENSUSE-SU-2020:2160-1
OPENSUSE-SU-2020:2194-1
OPENSUSE-SU-2020:2204-1
OPENSUSE-SU-2020:2226-1
OPENSUSE-SU-2020_2160-1
OPENSUSE-SU-2020_2194-1
OPENSUSE-SU-2021:0519-1
OPENSUSE-SU-2021:0545-1
OPENSUSE-SU-2021_0519-1
OPENSUSE-SU-2024:10837-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11050-1
RHSA-2021:1789
RHSA-2021_1789
RLSA-2021:1789
USN-4494-1
USN-4722-1
USN-4734-1
USN-4734-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Open Connectivity Foundation Upnp
Red Hat
Rocky Linux
Suse
Ubuntu
Windows 10
Xbox One
Cling