PT-2021-18232 · Unknown+2 · Portable Sdk For Upnp Devices+2

Medoc92

+1

·

Published

2021-04-20

·

Updated

2025-10-21

·

CVE-2021-29462

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Portable SDK for UPnP Devices versions prior to 1.14.6
Description: The server part of pupnp (libupnp) is susceptible to DNS rebinding attacks due to its failure to check the value of the Host header. This issue can be mitigated by utilizing DNS resolvers that block DNS-rebinding attacks.
Recommendations: For versions prior to 1.14.6, update to version 1.14.6 or later to resolve the issue. As a temporary workaround, consider using DNS resolvers that block DNS-rebinding attacks to minimize the risk of exploitation.

Fix

Insufficient Verification of Data Authenticity

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2022-7682
CVE-2021-29462
GHSA-6HQQ-W3JQ-9FHG
MGASA-2021-0319
OPENSUSE-SU-2024:11006-1

Affected Products

Alt Linux
Debian
Portable Sdk For Upnp Devices