Lucene search

K
cve[email protected]CVE-2011-4501
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-4501

2022-10-0316:15:14
CWE-16
web.nvd.nist.gov
24
cve
upnp
igd
vulnerability
routers
firmware
remote attackers
port mappings
soap request
wan interface

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an “external forwarding” vulnerability.

Affected configurations

NVD
Node
edimaxbr-6104k_router_firmwareMatch3.21
AND
edimaxbr-6104kMatch-
Node
canyon-techcn-wf512_router_firmwareMatch1.83
OR
canyon-techcn-wf514_router_firmwareMatch2.08
AND
canyon-techcn-wf512Match-
OR
canyon-techcn-wf514Match-
Node
edimax6114wg_router_firmwareMatch1.83
OR
edimax6114wg_router_firmwareMatch2.08
AND
edimax6114wgMatch-
Node
sitecomwl-153_router_firmwareMatch1.31
OR
sitecomwl-153_router_firmwareMatch1.34
AND
sitecomwl-153Match-
Node
sweexlb000021_router_firmwareMatch3.15
AND
sweexlb000021Match-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%

Related for CVE-2011-4501