CVE-2020-12695
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Linuxmint, Open Connectivity Foundation Upnp, Red Hat
- Ui Unifi Controller
- All versions
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 15.2% (97th percentile)
- Weakness
- CWE-276
- NVD status
- Modified
- Published
- 2020-06-08
CVE-2020-12695 at NVD
5 known exploits for CVE-2020-12695
Proof-of-concept code and exploit modules indexed by Sploitus