The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Project Subscriptions

Vendors Products
Broadcom Subscribe
Selphy Cp1200 Subscribe
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
B1165nfw Subscribe
Dvg-n5412sp Subscribe
Fedoraproject Subscribe
5020 Z4a69a Subscribe
5030 M2u92b Subscribe
5030 Z4a70a Subscribe
5034 Z4a74a Subscribe
5660 F8b04a Subscribe
Deskjet Ink Advantage 3456 A9t84c Subscribe
Deskjet Ink Advantage 3545 A9t81a Subscribe
Deskjet Ink Advantage 3545 A9t81c Subscribe
Deskjet Ink Advantage 3545 A9t83b Subscribe
Deskjet Ink Advantage 3546 A9t82a Subscribe
Deskjet Ink Advantage 3548 A9t81b Subscribe
Deskjet Ink Advantage 4515 Subscribe
Deskjet Ink Advantage 4518 Subscribe
Deskjet Ink Advantage 4535 F0v64a Subscribe
Deskjet Ink Advantage 4535 F0v64b Subscribe
Deskjet Ink Advantage 4535 F0v64c Subscribe
Deskjet Ink Advantage 4536 F0v65a Subscribe
Deskjet Ink Advantage 4538 F0v66b Subscribe
Deskjet Ink Advantage 4675 F1h97a Subscribe
Deskjet Ink Advantage 4675 F1h97b Subscribe
Deskjet Ink Advantage 4675 F1h97c Subscribe
Deskjet Ink Advantage 4676 F1h98a Subscribe
Deskjet Ink Advantage 4678 F1h99b Subscribe
Deskjet Ink Advantage 5575 G0v48b Subscribe
Deskjet Ink Advantage 5575 G0v48c Subscribe
Envy 100 Cn517a Subscribe
Envy 100 Cn517b Subscribe
Envy 100 Cn517c Subscribe
Envy 100 Cn518a Subscribe
Envy 100 Cn519a Subscribe
Envy 100 Cn519b Subscribe
Envy 110 Cq809a Subscribe
Envy 110 Cq809b Subscribe
Envy 110 Cq809c Subscribe
Envy 110 Cq809d Subscribe
Envy 110 Cq812c Subscribe
Envy 111 Cq810a Subscribe
Envy 114 Cq811a Subscribe
Envy 114 Cq811b Subscribe
Envy 114 Cq812a Subscribe
Envy 120 Cz022a Subscribe
Envy 120 Cz022b Subscribe
Envy 120 Cz022c Subscribe
Envy 4500 A9t80a Subscribe
Envy 4500 A9t80b Subscribe
Envy 4500 A9t89a Subscribe
Envy 4500 D3p93a Subscribe
Envy 4501 C8d05a Subscribe
Envy 4502 A9t85a Subscribe
Envy 4502 A9t87b Subscribe
Envy 4503 E6g71b Subscribe
Envy 4504 A9t88b Subscribe
Envy 4504 C8d04a Subscribe
Envy 4505 A9t86a Subscribe
Envy 4507 E6g70b Subscribe
Envy 4508 E6g72b Subscribe
Envy 4509 D3p94a Subscribe
Envy 4509 D3p94b Subscribe
Envy 4511 K9h50a Subscribe
Envy 4512 K9h49a Subscribe
Envy 4513 K9h51a Subscribe
Envy 4516 K9h52a Subscribe
Envy 4520 E6g67a Subscribe
Envy 4520 E6g67b Subscribe
Envy 4520 F0v63a Subscribe
Envy 4520 F0v63b Subscribe
Envy 4520 F0v69a Subscribe
Envy 4521 K9t10b Subscribe
Envy 4522 F0v67a Subscribe
Envy 4523 J6u60b Subscribe
Envy 4524 F0v71b Subscribe
Envy 4524 F0v72b Subscribe
Envy 4524 K9t01a Subscribe
Envy 4525 K9t09b Subscribe
Envy 4526 K9t05b Subscribe
Envy 4527 J6u61b Subscribe
Envy 4528 K9t08b Subscribe
Envy 5000 M2u85a Subscribe
Envy 5000 M2u85b Subscribe
Envy 5000 M2u91a Subscribe
Envy 5000 M2u94b Subscribe
Envy 5000 Z4a54a Subscribe
Envy 5000 Z4a74a Subscribe
Envy 5020 M2u91b Subscribe
Envy 5530 Subscribe
Envy 5531 Subscribe
Envy 5532 Subscribe
Envy 5534 Subscribe
Envy 5535 Subscribe
Envy 5536 Subscribe
Envy 5539 Subscribe
Envy 5540 F2e72a Subscribe
Envy 5540 G0v47a Subscribe
Envy 5540 G0v51a Subscribe
Envy 5540 G0v52a Subscribe
Envy 5540 G0v53a Subscribe
Envy 5540 K7c85a Subscribe
Envy 5541 K7g89a Subscribe
Envy 5542 K7c88a Subscribe
Envy 5543 N9u88a Subscribe
Envy 5544 K7c89a Subscribe
Envy 5544 K7c93a Subscribe
Envy 5545 G0v50a Subscribe
Envy 5546 K7c90a Subscribe
Envy 5547 J6u64a Subscribe
Envy 5548 K7g87a Subscribe
Envy 5640 B9s56a Subscribe
Envy 5640 B9s58a Subscribe
Envy 5642 B9s64a Subscribe
Envy 5643 B9s63a Subscribe
Envy 5644 B9s65a Subscribe
Envy 5646 F8b05a Subscribe
Envy 5664 F8b08a Subscribe
Envy 5665 F8b06a Subscribe
Envy 6020 5se16b Subscribe
Envy 6020 5se17a Subscribe
Envy 6020 6wd35a Subscribe
Envy 6020 7cz37a Subscribe
Envy 6052 5se18a Subscribe
Envy 6055 5se16a Subscribe
Envy 6540 B9s59a Subscribe
Envy 7640 Subscribe
Envy 7644 E4w46a Subscribe
Envy 7645 E4w44a Subscribe
Envy Photo 6200 K7g18a Subscribe
Envy Photo 6200 K7g26b Subscribe
Envy Photo 6200 K7s21b Subscribe
Envy Photo 6200 Y0k13d Subscribe
Envy Photo 6200 Y0k15a Subscribe
Envy Photo 6220 K7g20d Subscribe
Envy Photo 6220 K7g21b Subscribe
Envy Photo 6222 Y0k13d Subscribe
Envy Photo 6222 Y0k14d Subscribe
Envy Photo 6230 K7g25b Subscribe
Envy Photo 6232 K7g26b Subscribe
Envy Photo 6234 K7s21b Subscribe
Envy Photo 6252 K7g22a Subscribe
Envy Photo 7100 3xd89a Subscribe
Envy Photo 7100 K7g93a Subscribe
Envy Photo 7100 K7g99a Subscribe
Envy Photo 7100 Z3m37a Subscribe
Envy Photo 7100 Z3m52a Subscribe
Envy Photo 7120 Z3m41d Subscribe
Envy Photo 7155 Z3m52a Subscribe
Envy Photo 7164 K7g99a Subscribe
Envy Photo 7800 K7r96a Subscribe
Envy Photo 7800 K7s00a Subscribe
Envy Photo 7800 K7s10d Subscribe
Envy Photo 7800 Y0g42d Subscribe
Envy Photo 7800 Y0g52b Subscribe
Envy Photo 7822 Y0g42d Subscribe
Envy Photo 7822 Y0g43d Subscribe
Envy Photo 7830 Y0g50b Subscribe
Envy Pro 6420 5se45b Subscribe
Envy Pro 6420 5se46a Subscribe
Envy Pro 6420 6wd14a Subscribe
Envy Pro 6420 6wd16a Subscribe
Envy Pro 6452 5se47a Subscribe
Envy Pro 6455 5se45a Subscribe
Officejet 4650 E6g87a Subscribe
Officejet 4650 F1h96a Subscribe
Officejet 4650 F1h96b Subscribe
Officejet 4652 F1j02a Subscribe
Officejet 4652 F1j05b Subscribe
Officejet 4652 K9v84b Subscribe
Officejet 4654 F1j06b Subscribe
Officejet 4654 F1j07b Subscribe
Officejet 4655 F1j00a Subscribe
Officejet 4655 K9v79a Subscribe
Officejet 4655 K9v82b Subscribe
Officejet 4656 K9v81b Subscribe
Officejet 4657 V6d29b Subscribe
Officejet 4658 V6d30b Subscribe
Microsoft Subscribe
Windows 10 Subscribe
Xbox One Subscribe
Wr8165n Subscribe
Netgear Subscribe
Wnhde111 Subscribe
Enterprise Linux Subscribe
Ruckussecurity Subscribe
Zonedirector 1200 Subscribe
Tp-link Subscribe
Archer C50 Subscribe
Unifi Controller Subscribe
Hostapd Subscribe
Zxv10 W300 Subscribe
Amg1202-t10b Subscribe
Vmg8324-b10a Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2315-1 gupnp security update
Debian DLA Debian DLA DLA-2318-1 wpa security update
Debian DLA Debian DLA DLA-2489-1 minidlna security update
Debian DSA Debian DSA DSA-4806-1 minidlna security update
Debian DSA Debian DSA DSA-4898-1 wpa security update
Ubuntu USN Ubuntu USN USN-4494-1 GUPnP vulnerability
Ubuntu USN Ubuntu USN USN-4722-1 ReadyMedia (MiniDLNA) vulnerabilities
Ubuntu USN Ubuntu USN USN-4734-1 wpa_supplicant and hostapd vulnerabilities
Ubuntu USN Ubuntu USN USN-4734-2 wpa_supplicant and hostapd vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T12:04:22.578Z

Reserved: 2020-05-07T00:00:00

Link: CVE-2020-12695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-08T17:15:09.973

Modified: 2024-11-21T05:00:05.367

Link: CVE-2020-12695

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-06-08T00:00:00Z

Links: CVE-2020-12695 - Bugzilla

cve-icon OpenCVE Enrichment

No data.