Overview
The Universal Plug and Play (UPnP) protocol in effect prior to April 17, 2020 can be abused to send traffic to arbitrary destinations using the SUBSCRIBE functionality.
Description
The UPnP protocol, as specified by the Open Connectivity Foundation (OCF), is designed to provide automatic discovery and interaction with devices on a network. The UPnP protocol is designed to be used in a trusted local area network (LAN) and the protocol does not implement any form of authentication or verification.
Many common Internet-connected devices support UPnP, as noted in previous research from Daniel Garcia (VU#357851) and Rapid7. Garcia presented at DEFCON 2019 and published a scanning and portmapping tool. The UPnP Device Protection service was not widely adopted.
A vulnerability in the UPnP SUBSCRIBE capability permits an attacker to send large amounts of data to arbitrary destinations accessible over the Internet, which could lead to a Distributed Denial of Service (DDoS), data exfiltration, and other unexpected network behavior. The OCF has updated the UPnP specification to address this issue. This vulnerability has been assigned CVE-2020-12695 and is also known as Call Stranger.
Although offering UPnP services on the Internet is generally considered to be a misconfiguration, a number of devices are still available over the Internet according to a recent Shodan scan.
Impact
A remote, unauthenticated attacker may be able to abuse the UPnP SUBSCRIBE capability to send traffic to arbitrary destinations, leading to amplified DDoS attacks and data exfiltration. In general, making UPnP available over the the Internet can pose further security vulnerabilities than the one described in this vulnerability note.
Solution
Affected devices
A number of devices have been identified as vulnerable by the security researcher and have been posted at the CallStranger website. There is more information on affected devices in Tenable's blog on cve-2020-12695.
Apply updates
Vendors are urged to implement the updated specification provided by the OCF.. Users should monitor vendor support channels for updates that implement the new SUBSCRIBE specification.
Disable or Restrict UPnP
Disable the UPnP protocol on Internet-accessible interfaces. Device manufacturers are urged to disable the UPnP SUBSCRIBE capability in their default configuration and to require users to explicitly enable SUBSCRIBE with any appropriate network restrictions to limit its usage to a trusted local area network.
IDS Signature
This Surricata IDS rule looks for any HTTP SUBSCRIBE request to what is likely to be an external network (i.e., not RFC1918 and RFC4193 addresses). Network administrators and ISPs can deploy this signature at the Internet access point to detect any anomalous SUBSCRIBE requests reaching their users.
alert http any any -> ![fd00::/8,192.168.0.0/16,10.0.0.0/8,172.16.0.0/12] any (msg:"UPnP SUBSCRIBE request seen to external network VU#339275: CVE-
2020-12695 https://kb.cert.org "; content: "subscribe"; nocase; http_method; sid:1367339275;)
Acknowledgements
This vulnerability was reported by Yunus Çadirci from EY Turkey.
This document was written by Vijay Sarvepalli.
Vendor Information
Open Connectivity Foundation Affected
| CVE-2020-12695 | Affected |
Vendor Statement
We have not received a statement from the vendor.
References
CERT Addendum
Open Connectivity Foundation has updated their specification and published in the bulletin, see references.
Synology Affected
Statement Date: June 22, 2020
| CVE-2020-12695 | Affected |
Vendor Statement
Please refer to Synology-SA-20:13
References
Zyxel Affected
| CVE-2020-12695 | Affected |
Vendor Statement
Zyxel security team confirms that Zyxel’s VMG8324-B10A has the default firewall rule to block UPnP traffic from WAN since its first firmware V1.00(AAKL.0)C0 released in May 2013. However, if users intentionally disable the firewall feature, it could be vulnerable.
References
CERT Addendum
Users are urged to not disable firewall to reduce the impact of this vulnerability from the WAN interface. Check Zyxel advisories for regular updates.
hostapd Affected
| CVE-2020-12695 | Affected |
Vendor Statement
We have not received a statement from the vendor.
References
CERT Addendum
HostAP has released a statement and patches, see the References section for details.
Commscope Not Affected
| CVE-2020-12695 | Not Affected |
Vendor Statement
None of the Ruckus products are vulnerable to CVE-2020-12695
CERT Addendum
Commscope acquired Arris and Ruckus Wireless. Announcements may be duplicated in the brand named vendor sections.
Cradlepoint Not Affected
| CVE-2020-12695 | Not Affected |
Vendor Statement
In NCOS, UPnP Gateway is disabled and the zone-based firewall is configured with an explicit deny for unsolicited inbound traffic by default
References
LANCOM Systems GmbH Not Affected
| CVE-2020-12695 | Not Affected |
Vendor Statement
LANCOM Systems products are not vulnerable to these vulnerabilities.
Peplink Not Affected
Statement Date: July 07, 2020
| CVE-2020-12695 | Not Affected |
Vendor Statement
We have not received a statement from the vendor.
Ruckus Wireless Not Affected
| CVE-2020-12695 | Not Affected |
Vendor Statement
None of the Ruckus products are vulnerable to CVE-2020-12695
References
CERT Addendum
Please note that Commscope acquired Ruckus Wireless in 2019. You may see future advisory under Commscope.
Sierra Wireless Not Affected
| CVE-2020-12695 | Not Affected |
Vendor Statement
We have not received a statement from the vendor.
A10 Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ACCESS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ADATA Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ADTRAN Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ANTlabs Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ARRIS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ASUSTeK Computer Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AT&T Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AVM GmbH Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Actelis Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Actiontec Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aerohive Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AhnLab Inc Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
AirWatch Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Akamai Technologies Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Alcatel-Lucent Enterprise Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Allied Telesis Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Amazon Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Android Open Source Project Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Apple Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Arista Networks Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aruba Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Aspera Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Barracuda Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Belden Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Belkin Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BlackBerry Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Blue Coat Systems Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BlueCat Networks Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Blunk Microsystems Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
BoringSSL Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Broadcom Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CA Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CMX Systems Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CZ.NIC Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cambium Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ceragon Networks Inc Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Check Point Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cirpack Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cisco Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Contiki OS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
CoreOS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cricket Wireless Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Cypress Semiconductor Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
D-Link Systems Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Debian GNU/Linux Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell EMC Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Dell SecureWorks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
DesktopBSD Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Deutsche Telekom Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Devicescape Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Digi International Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
DragonFly BSD Project Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
ENEA Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
EfficientIP Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ericsson Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Espressif Systems Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
European Registry for Internet Domains Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Express Logic Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Extreme Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
F-Secure Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fastly Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fedora Project Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Force10 Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Fortinet Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Foundry Brocade Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
FreeBSD Project Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GFI Software Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GNU adns Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
GNU glibc Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Geexbox Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Gentoo Linux Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Google Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Grandstream Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Green Hills Software Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HCC Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HP Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
HTC Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Hewlett Packard Enterprise Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Hitachi Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Honeywell Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Huawei Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
IBM Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
INTEROP Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
IP Infusion Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Illumos Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
InfoExpress Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Infoblox Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Inmarsat Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Intel Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Internet Systems Consortium - DHCP Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
JH Software Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Joyent Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Juniper Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LG Electronics Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LITE-ON Technology Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lancope Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lantronix Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lenovo Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
LiteSpeed Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Lynx Software Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Marvell Semiconductor Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
McAfee Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
MediaTek Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Medtronic Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Men & Mice Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Micro Focus Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Microchip Technology Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Microsoft Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
MikroTik Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Miredo Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Mitel Networks Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Muonics Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NEC Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NETSCOUT Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NIKSUN Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
NLnet Labs Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Netgear Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Nokia Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Nominum Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OleumTech Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenBSD Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenSSL Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
OpenWRT Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Oracle Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Oryx Embedded Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
PHPIDS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Paessler Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Palo Alto Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Philips Electronics Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Proxim Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Pulse Secure Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QLogic Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QNX Software Systems Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
QUALCOMM Incorporated Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Quadros Systems Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Quagga Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Red Hat Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Riverbed Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Rocket RTOS (Inactive) Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Roku Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SEIKO EPSON Corp. / Epson America Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SMC Networks Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SUSE Linux Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SafeNet Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Samsung Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Samsung Mobile Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Secure64 Software Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Slackware Linux Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Snort Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
SonicWall Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sonos Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sony Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sophos Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Sourcefire Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Symantec Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TDS Telecom Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TP-LINK Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Technicolor Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Tenable Network Security Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
TippingPoint Technologies Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Treck Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Turbolinux Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ubiquiti Networks Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Ubuntu Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Unisys Corporation Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Untangle Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
VMware Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Vertical Networks Inc. Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Wind River Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
WizNET Technology Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
XigmaNAS Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Xilinx Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Zebra Technologies Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
Zephyr Project Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
dd-wrt Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
dnsmasq Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
eCosCentric Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
eero Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
lwIP Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
m0n0wall Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
netsnmp Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
pfSense Unknown
| CVE-2020-12695 | Unknown |
Vendor Statement
We have not received a statement from the vendor.
References
- https://callstranger.com
- https://openconnectivity.org/developer/specifications/upnp-resources/upnp/
- https://kb.cert.org/vuls/search/?q=upnp
- https://github.com/yunuscadirci/CallStranger
- https://www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of
Other Information
| CVE IDs: | CVE-2020-12695 |
| Date Public: | 2020-06-08 |
| Date First Published: | 2020-06-08 |
| Date Last Updated: | 2020-07-08 21:44 UTC |
| Document Revision: | 14 |