7.8

CVE-2020-12695

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Data is provided by the National Vulnerability Database (NVD)
UiUnifi Controller Version-
W1.FiHostapd Version < 2.0.0
AsusRt-n11 Version-
BroadcomAdsl Version-
CanonSelphy Cp1200 Version-
CiscoWap131 Version-
CiscoWap150 Version-
CiscoWap351 Version-
DlinkDvg-n5412sp Version-
DellB1165nfw Version-
EpsonEp-101 Version-
EpsonEw-m970a3t Version-
EpsonM571t Version-
EpsonXp-100 Version-
EpsonXp-2101 Version-
EpsonXp-2105 Version-
EpsonXp-241 Version-
EpsonXp-320 Version-
EpsonXp-330 Version-
EpsonXp-340 Version-
EpsonXp-4100 Version-
EpsonXp-4105 Version-
EpsonXp-440 Version-
EpsonXp-620 Version-
EpsonXp-630 Version-
EpsonXp-702 Version-
EpsonXp-8500 Version-
EpsonXp-8600 Version-
EpsonXp-960 Version-
EpsonXp-970 Version-
Hp5020 Z4a69a Version-
Hp5030 M2u92b Version-
Hp5030 Z4a70a Version-
Hp5034 Z4a74a Version-
Hp5660 F8b04a Version-
HpEnvy 100 Cn517a Version-
HpEnvy 100 Cn517b Version-
HpEnvy 100 Cn517c Version-
HpEnvy 100 Cn518a Version-
HpEnvy 100 Cn519a Version-
HpEnvy 100 Cn519b Version-
HpEnvy 110 Cq809a Version-
HpEnvy 110 Cq809b Version-
HpEnvy 110 Cq809c Version-
HpEnvy 110 Cq809d Version-
HpEnvy 110 Cq812c Version-
HpEnvy 111 Cq810a Version-
HpEnvy 114 Cq811a Version-
HpEnvy 114 Cq811b Version-
HpEnvy 114 Cq812a Version-
HpEnvy 120 Cz022a Version-
HpEnvy 120 Cz022b Version-
HpEnvy 120 Cz022c Version-
HpEnvy 4500 A9t80a Version-
HpEnvy 4500 A9t80b Version-
HpEnvy 4500 A9t89a Version-
HpEnvy 4500 D3p93a Version-
HpEnvy 4501 C8d05a Version-
HpEnvy 4502 A9t85a Version-
HpEnvy 4502 A9t87b Version-
HpEnvy 4503 E6g71b Version-
HpEnvy 4504 A9t88b Version-
HpEnvy 4504 C8d04a Version-
HpEnvy 4505 A9t86a Version-
HpEnvy 4507 E6g70b Version-
HpEnvy 4508 E6g72b Version-
HpEnvy 4509 D3p94a Version-
HpEnvy 4509 D3p94b Version-
HpEnvy 4511 K9h50a Version-
HpEnvy 4512 K9h49a Version-
HpEnvy 4513 K9h51a Version-
HpEnvy 4516 K9h52a Version-
HpEnvy 4520 E6g67a Version-
HpEnvy 4520 E6g67b Version-
HpEnvy 4520 F0v63a Version-
HpEnvy 4520 F0v63b Version-
HpEnvy 4520 F0v69a Version-
HpEnvy 4521 K9t10b Version-
HpEnvy 4522 F0v67a Version-
HpEnvy 4523 J6u60b Version-
HpEnvy 4524 F0v71b Version-
HpEnvy 4524 F0v72b Version-
HpEnvy 4524 K9t01a Version-
HpEnvy 4525 K9t09b Version-
HpEnvy 4526 K9t05b Version-
HpEnvy 4527 J6u61b Version-
HpEnvy 4528 K9t08b Version-
HpEnvy 5000 M2u85a Version-
HpEnvy 5000 M2u85b Version-
HpEnvy 5000 M2u91a Version-
HpEnvy 5000 M2u94b Version-
HpEnvy 5000 Z4a54a Version-
HpEnvy 5000 Z4a74a Version-
HpEnvy 5020 M2u91b Version-
HpEnvy 5530 Version-
HpEnvy 5531 Version-
HpEnvy 5532 Version-
HpEnvy 5534 Version-
HpEnvy 5535 Version-
HpEnvy 5536 Version-
HpEnvy 5539 Version-
HpEnvy 5540 F2e72a Version-
HpEnvy 5540 G0v47a Version-
HpEnvy 5540 G0v51a Version-
HpEnvy 5540 G0v52a Version-
HpEnvy 5540 G0v53a Version-
HpEnvy 5540 K7c85a Version-
HpEnvy 5541 K7g89a Version-
HpEnvy 5542 K7c88a Version-
HpEnvy 5543 N9u88a Version-
HpEnvy 5544 K7c89a Version-
HpEnvy 5544 K7c93a Version-
HpEnvy 5545 G0v50a Version-
HpEnvy 5546 K7c90a Version-
HpEnvy 5547 J6u64a Version-
HpEnvy 5548 K7g87a Version-
HpEnvy 5640 B9s56a Version-
HpEnvy 5640 B9s58a Version-
HpEnvy 5642 B9s64a Version-
HpEnvy 5643 B9s63a Version-
HpEnvy 5644 B9s65a Version-
HpEnvy 5646 F8b05a Version-
HpEnvy 5664 F8b08a Version-
HpEnvy 5665 F8b06a Version-
HpEnvy 6020 5se16b Version-
HpEnvy 6020 5se17a Version-
HpEnvy 6020 6wd35a Version-
HpEnvy 6020 7cz37a Version-
HpEnvy 6052 5se18a Version-
HpEnvy 6055 5se16a Version-
HpEnvy 6540 B9s59a Version-
HpEnvy 7640 Version-
HpEnvy 7644 E4w46a Version-
HpEnvy 7645 E4w44a Version-
HpEnvy Photo 6200 K7g18a Version-
HpEnvy Photo 6200 K7g26b Version-
HpEnvy Photo 6200 K7s21b Version-
HpEnvy Photo 6200 Y0k15a Version-
HpEnvy Photo 6220 K7g20d Version-
HpEnvy Photo 6220 K7g21b Version-
HpEnvy Photo 6222 Y0k13d Version-
HpEnvy Photo 6222 Y0k14d Version-
HpEnvy Photo 6230 K7g25b Version-
HpEnvy Photo 6232 K7g26b Version-
HpEnvy Photo 6234 K7s21b Version-
HpEnvy Photo 6252 K7g22a Version-
HpEnvy Photo 7100 3xd89a Version-
HpEnvy Photo 7100 K7g93a Version-
HpEnvy Photo 7100 K7g99a Version-
HpEnvy Photo 7100 Z3m37a Version-
HpEnvy Photo 7100 Z3m52a Version-
HpEnvy Photo 7120 Z3m41d Version-
HpEnvy Photo 7155 Z3m52a Version-
HpEnvy Photo 7164 K7g99a Version-
HpEnvy Photo 7800 K7r96a Version-
HpEnvy Photo 7800 K7s00a Version-
HpEnvy Photo 7800 K7s10d Version-
HpEnvy Photo 7800 Y0g42d Version-
HpEnvy Photo 7800 Y0g52b Version-
HpEnvy Photo 7822 Y0g42d Version-
HpEnvy Photo 7822 Y0g43d Version-
HpEnvy Photo 7830 Y0g50b Version-
HpEnvy Pro 6420 5se45b Version-
HpEnvy Pro 6420 5se46a Version-
HpEnvy Pro 6420 6wd14a Version-
HpEnvy Pro 6420 6wd16a Version-
HpEnvy Pro 6452 5se47a Version-
HpEnvy Pro 6455 5se45a Version-
HpOfficejet 4650 E6g87a Version-
HpOfficejet 4650 F1h96a Version-
HpOfficejet 4650 F1h96b Version-
HpOfficejet 4652 F1j02a Version-
HpOfficejet 4652 F1j05b Version-
HpOfficejet 4652 K9v84b Version-
HpOfficejet 4654 F1j06b Version-
HpOfficejet 4654 F1j07b Version-
HpOfficejet 4655 F1j00a Version-
HpOfficejet 4655 K9v79a Version-
HpOfficejet 4655 K9v82b Version-
HpOfficejet 4656 K9v81b Version-
HpOfficejet 4657 V6d29b Version-
HpOfficejet 4658 V6d30b Version-
HuaweiHg255s Version-
HuaweiHg532e Version-
NecWr8165n Version-
NetgearWnhde111 Version-
Tp-linkArcher C50 Version-
ZteZxv10 W300 Version-
ZyxelAmg1202-t10b Version-
ZyxelVmg8324-b10a Version-
MicrosoftWindows 10 Version-
MicrosoftXbox One Version10.0.19041.2494
FedoraprojectFedora Version31
FedoraprojectFedora Version32
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
CanonicalUbuntu Linux Version20.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.73% 0.89
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H
nvd@nist.gov 7.8 8.6 7.8
AV:N/AC:M/Au:N/C:P/I:N/A:C
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://usn.ubuntu.com/4494-1/
Third Party Advisory
https://www.kb.cert.org/vuls/id/339275
Third Party Advisory
US Government Resource