Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-29462
HistoryApr 20, 2021 - 12:00 a.m.

CVE-2021-29462

2021-04-2000:00:00
ubuntu.com
ubuntu.com
4
portable sdk
upnp devices
dns rebinding
host header
dns resolvers
vulnerable
fixed

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.6%

The Portable SDK for UPnP Devices is an SDK for development of UPnP device
and control point applications. The server part of pupnp (libupnp) appears
to be vulnerable to DNS rebinding attacks because it does not check the
value of the Host header. This can be mitigated by using DNS revolvers
which block DNS-rebinding attacks. The vulnerability is fixed in version
1.14.6 and later.

Bugs

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.6%