The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
User | URL | Info Source | Date |
---|---|---|---|
VulmonFeeds | http://vulmon.com/vulnerabilitydetails?qid=CVE-2020-12695 | Source VulmonFeeds 1493608526186528777 | 2022/02/16 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
lists.astaro.com | 27 |
newsbythehour.org | 27 |
www.helpnetsecurity.com | 7 |
github.com | 5 |
kb.cert.org | 4 |
twitter.com | 3 |
www.tenable.com | 3 |
callstranger.com | 3 |
www.callstranger.com | 3 |
User | URL | Info Source |
---|---|---|
VulmonFeeds | vulmon.com | Show Tweet |
Name | URL |
---|---|
No Data |
Name | URL |
---|---|
No Data |