Описание
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
Ссылки
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.4 (исключая)
cpe:2.3:a:npupnp_project:npupnp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00479
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-346
Связанные уязвимости
github
больше 3 лет назад
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
EPSS
Процентиль: 64%
0.00479
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-346