The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2315-1 gupnp security update
Debian DLA Debian DLA DLA-2318-1 wpa security update
Debian DLA Debian DLA DLA-2489-1 minidlna security update
Debian DSA Debian DSA DSA-4806-1 minidlna security update
Debian DSA Debian DSA DSA-4898-1 wpa security update
Ubuntu USN Ubuntu USN USN-4494-1 GUPnP vulnerability
Ubuntu USN Ubuntu USN USN-4722-1 ReadyMedia (MiniDLNA) vulnerabilities
Ubuntu USN Ubuntu USN USN-4734-1 wpa_supplicant and hostapd vulnerabilities
Ubuntu USN Ubuntu USN USN-4734-2 wpa_supplicant and hostapd vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T12:04:22.578Z

Reserved: 2020-05-07T00:00:00

Link: CVE-2020-12695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-08T17:15:09.973

Modified: 2024-11-21T05:00:05.367

Link: CVE-2020-12695

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-06-08T00:00:00Z

Links: CVE-2020-12695 - Bugzilla

cve-icon OpenCVE Enrichment

No data.