CVE-2020-23622
Dashboard / Vulnerabilities / CVE-2020-23622
Summary:
Details: An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header
References: https://github.com/4thline/cling/issues/253, https://zh-cn.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of?tns_redirect=true
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 5fd60eb9e2e87f2ae6d1cf049145c4187040518c
Fixed -None
Affected versions
2.1.2
2.1.1
2.1.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
