Overview
The Universal Plug and Play (UPnP) protocol in effect prior to April 17, 2020 can be abused to send traffic to arbitrary destinations using the SUBSCRIBE functionality.
Description
The UPnP protocol, as specified by the Open Connectivity Foundation (OCF), is designed to provide automatic discovery and interaction with devices on a network. The UPnP protocol is designed to be used in a trusted local area network (LAN) and the protocol does not implement any form of authentication or verification.
Many common Internet-connected devices support UPnP, as noted in previous research from Daniel Garcia (VU#357851) and Rapid7. Garcia presented at DEFCON 2019 and published a scanning and portmapping tool. The UPnP Device Protection service was not widely adopted.
A vulnerability in the UPnP SUBSCRIBE capability permits an attacker to send large amounts of data to arbitrary destinations accessible over the Internet, which could lead to a Distributed Denial of Service (DDoS), data exfiltration, and other unexpected network behavior. The OCF has updated the UPnP specification to address this issue. This vulnerability has been assigned CVE-2020-12695 and is also known as Call Stranger.
Although offering UPnP services on the Internet is generally considered to be a misconfiguration, a number of devices are still available over the Internet according to a recent Shodan scan.
Impact
A remote, unauthenticated attacker may be able to abuse the UPnP SUBSCRIBE capability to send traffic to arbitrary destinations, leading to amplified DDoS attacks and data exfiltration. In general, making UPnP available over the the Internet can pose further security vulnerabilities than the one described in this vulnerability note.
Solution
Affected devices
A number of devices have been identified as vulnerable by the security researcher and have been posted at the CallStranger website. There is more information on affected devices in Tenable's blog on cve-2020-12695.
Apply updates
Vendors are urged to implement the updated specification provided by the OCF.. Users should monitor vendor support channels for updates that implement the new SUBSCRIBE specification.
Disable or Restrict UPnP
Disable the UPnP protocol on Internet-accessible interfaces. Device manufacturers are urged to disable the UPnP SUBSCRIBE capability in their default configuration and to require users to explicitly enable SUBSCRIBE with any appropriate network restrictions to limit its usage to a trusted local area network.
IDS Signature
This Surricata IDS rule looks for any HTTP SUBSCRIBE request to what is likely to be an external network (i.e., not RFC1918 and RFC4193 addresses). Network administrators and ISPs can deploy this signature at the Internet access point to detect any anomalous SUBSCRIBE requests reaching their users.
alert http any any -> ![fd00::/8,192.168.0.0/16,10.0.0.0/8,172.16.0.0/12] any (msg:"UPnP SUBSCRIBE request seen to external network VU#339275: CVE-
2020-12695 https://kb.cert.org "; content: "subscribe"; nocase; http_method; sid:1367339275;)
Acknowledgements
This vulnerability was reported by Yunus Çadirci from EY Turkey.
This document was written by Vijay Sarvepalli.
Vendor Information
Open Connectivity Foundation Affected
CVE-2020-12695 | Affected |
Vendor Statement
We have not received a statement from the vendor.
References
CERT Addendum
Open Connectivity Foundation has updated their specification and published in the bulletin, see references.
Synology Affected
Statement Date: June 22, 2020
CVE-2020-12695 | Affected |
Vendor Statement
Please refer to Synology-SA-20:13
References
Zyxel Affected
CVE-2020-12695 | Affected |
Vendor Statement
Zyxel security team confirms that Zyxel’s VMG8324-B10A has the default firewall rule to block UPnP traffic from WAN since its first firmware V1.00(AAKL.0)C0 released in May 2013. However, if users intentionally disable the firewall feature, it could be vulnerable.
References
CERT Addendum
Users are urged to not disable firewall to reduce the impact of this vulnerability from the WAN interface. Check Zyxel advisories for regular updates.
hostapd Affected
CVE-2020-12695 | Affected |
Vendor Statement
We have not received a statement from the vendor.
References
CERT Addendum
HostAP has released a statement and patches, see the References section for details.
Commscope Not Affected
CVE-2020-12695 | Not Affected |
Vendor Statement
None of the Ruckus products are vulnerable to CVE-2020-12695
CERT Addendum
Commscope acquired Arris and Ruckus Wireless. Announcements may be duplicated in the brand named vendor sections.
Cradlepoint Not Affected
CVE-2020-12695 | Not Affected |
Vendor Statement
In NCOS, UPnP Gateway is disabled and the zone-based firewall is configured with an explicit deny for unsolicited inbound traffic by default
References
LANCOM Systems GmbH Not Affected
CVE-2020-12695 | Not Affected |
Vendor Statement
LANCOM Systems products are not vulnerable to these vulnerabilities.
Peplink Not Affected
Statement Date: July 07, 2020
CVE-2020-12695 | Not Affected |
Vendor Statement
We have not received a statement from the vendor.
Ruckus Wireless Not Affected
CVE-2020-12695 | Not Affected |
Vendor Statement
None of the Ruckus products are vulnerable to CVE-2020-12695
References
CERT Addendum
Please note that Commscope acquired Ruckus Wireless in 2019. You may see future advisory under Commscope.
Sierra Wireless Not Affected
CVE-2020-12695 | Not Affected |
Vendor Statement
We have not received a statement from the vendor.
A10 Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ACCESS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ADATA Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ADTRAN Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ANTlabs Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ARRIS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ASUSTeK Computer Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AT&T Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AVM GmbH Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Actelis Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Actiontec Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aerohive Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AhnLab Inc Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AirWatch Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Akamai Technologies Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Alcatel-Lucent Enterprise Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Allied Telesis Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Amazon Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Android Open Source Project Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Apple Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Arista Networks Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aruba Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aspera Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Barracuda Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Belden Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Belkin Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BlackBerry Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Blue Coat Systems Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BlueCat Networks Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Blunk Microsystems Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BoringSSL Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Broadcom Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CA Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CMX Systems Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CZ.NIC Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cambium Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ceragon Networks Inc Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Check Point Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cirpack Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cisco Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Contiki OS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CoreOS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cricket Wireless Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cypress Semiconductor Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
D-Link Systems Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Debian GNU/Linux Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell EMC Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell SecureWorks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
DesktopBSD Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Deutsche Telekom Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Devicescape Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Digi International Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
DragonFly BSD Project Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ENEA Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
EfficientIP Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ericsson Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Espressif Systems Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
European Registry for Internet Domains Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Express Logic Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Extreme Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
F-Secure Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fastly Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fedora Project Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Force10 Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fortinet Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Foundry Brocade Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
FreeBSD Project Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GFI Software Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GNU adns Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GNU glibc Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Geexbox Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Gentoo Linux Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Google Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Grandstream Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Green Hills Software Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HCC Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HP Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HTC Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Hewlett Packard Enterprise Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Hitachi Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Honeywell Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Huawei Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
IBM Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
INTEROP Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
IP Infusion Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Illumos Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
InfoExpress Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Infoblox Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Inmarsat Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Intel Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Internet Systems Consortium - DHCP Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
JH Software Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Joyent Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Juniper Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LG Electronics Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LITE-ON Technology Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lancope Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lantronix Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lenovo Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LiteSpeed Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lynx Software Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Marvell Semiconductor Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
McAfee Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
MediaTek Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Medtronic Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Men & Mice Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Micro Focus Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Microchip Technology Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Microsoft Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
MikroTik Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Miredo Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Mitel Networks Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Muonics Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NEC Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NETSCOUT Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NIKSUN Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NLnet Labs Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Netgear Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Nokia Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Nominum Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OleumTech Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenBSD Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenSSL Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenWRT Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Oracle Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Oryx Embedded Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
PHPIDS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Paessler Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Palo Alto Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Philips Electronics Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Proxim Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Pulse Secure Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QLogic Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QNX Software Systems Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QUALCOMM Incorporated Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Quadros Systems Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Quagga Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Red Hat Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Riverbed Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Rocket RTOS (Inactive) Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Roku Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SEIKO EPSON Corp. / Epson America Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SMC Networks Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SUSE Linux Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SafeNet Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Samsung Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Samsung Mobile Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Secure64 Software Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Slackware Linux Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Snort Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SonicWall Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sonos Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sony Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sophos Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sourcefire Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Symantec Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TDS Telecom Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TP-LINK Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Technicolor Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Tenable Network Security Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TippingPoint Technologies Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Treck Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Turbolinux Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ubiquiti Networks Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ubuntu Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Unisys Corporation Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Untangle Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
VMware Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Vertical Networks Inc. Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Wind River Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
WizNET Technology Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
XigmaNAS Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Xilinx Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Zebra Technologies Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Zephyr Project Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
dd-wrt Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
dnsmasq Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
eCosCentric Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
eero Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
lwIP Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
m0n0wall Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
netsnmp Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
pfSense Unknown
CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
References
- https://callstranger.com
- https://openconnectivity.org/developer/specifications/upnp-resources/upnp/
- https://kb.cert.org/vuls/search/?q=upnp
- https://github.com/yunuscadirci/CallStranger
- https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of
Other Information
CVE IDs: | CVE-2020-12695 |
Date Public: | 2020-06-08 |
Date First Published: | 2020-06-08 |
Date Last Updated: | 2020-07-08 21:44 UTC |
Document Revision: | 14 |