8.8
CVE-2021-31718
- EPSS 0.48%
- Veröffentlicht 25.04.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:06:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Npupnp Project ≫ Npupnp Version < 4.1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.622 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.