Описание
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
Ссылки
- Press/Media CoverageThird Party Advisory
- Press/Media CoverageThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:sonos:sonos_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:sonos:sonos:-:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00263
Низкий
9.6 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 9.6
github
больше 3 лет назад
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
EPSS
Процентиль: 49%
0.00263
Низкий
9.6 Critical
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-20