Input validation error in Universal Plug and Play (UPnP) - CVE-2020-12695

 

Input validation error in Universal Plug and Play (UPnP) - CVE-2020-12695

Published: June 10, 2020 / Updated: August 7, 2022


Vulnerability identifier: #VU28948
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12695
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a distributed denial of service (DDoS) attack.

The vulnerability exists due to a CallStranger issue in the UPnP SUBSCRIBE functionality. A remote attacker can send traffic to arbitrary destinations, leading to amplified DDoS attacks and data exfiltration.


Affected software

Universal Plug and Play (UPnP)
Huawei E6878-370
Debian Linux
Arch Linux
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Slackware Linux
Ubuntu
openEuler
minidlna (Debian package)
minidlna (Alpine package)
hostapd (Alpine package)
gssdp
gssdp (Red Hat package)
gupnp
gupnp (Red Hat package)
minidlna (Ubuntu package)
libgupnp-1.2-0 (Ubuntu package)
gupnp-debuginfo
gupnp-debugsource
gupnp-devel
gupnp-help
hostapd (Ubuntu package)
wpasupplicant (Ubuntu package)
wpa (Debian package)
hostapd

How to mitigate CVE-2020-12695

Install updates from vendor's website.

Universal Plug and Play (UPnP) - update to 2020-04-17
Huawei E6878-370 - update to 10.0.5.1(H612SP5C233)
minidlna (Debian package) - update to 1.2.1+dfsg-2+deb10u1
minidlna (Alpine package) - update to 1.2.1-r2
hostapd (Alpine package) - update to 2.7-r6
gssdp - addressed in versions 1.0.4-1.fc31, 1.0.4-1.fc32
gssdp (Red Hat package) - update to 1.0.5-1.el8
gupnp - addressed in versions 1.0.5-1.fc31, 1.0.5-1.fc32
gupnp (Red Hat package) - update to 1.0.6-1.el8
minidlna (Ubuntu package) - addressed in versions 1.1.5+dfsg-2ubuntu0.1, 1.2.1+dfsg-2ubuntu0.1, 1.2.1+dfsg-1ubuntu0.18.04.1, 1.2.1+dfsg-1ubuntu0.20.04.1
libgupnp-1.2-0 (Ubuntu package) - update to 1.2.3-0ubuntu0.20.04.1
gupnp-debuginfo - update to 1.2.4-1
gupnp-debugsource - update to 1.2.4-1
gupnp-devel - update to 1.2.4-1
gupnp - update to 1.2.4-1
gupnp-help - update to 1.2.4-1
hostapd (Ubuntu package) - addressed in versions 1:2.1-0ubuntu1.7+esm3, 1:2.4-0ubuntu6.7, 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1
wpasupplicant (Ubuntu package) - addressed in versions 2.1-0ubuntu1.7+esm3, 2.4-0ubuntu6.7, 2:2.6-15ubuntu2.7, 2:2.9-1ubuntu4.2, 2:2.9-1ubuntu8.1
wpa (Debian package) - update to 2:2.7+git20190128+0c1e29f-6+deb10u3
hostapd - addressed in versions 2.9-3.el7, 2.9-4.el8, 2.9-4.fc32

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins