CVE-2020-12695

HIGHCVSS 7.5/10EPSS 15.19%

Last modified

CVE-2020-12695 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.. EPSS estimates a 15.19% chance of exploitation in the next 30 days.

Description

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:H

EPSS Probability
15.19%

96.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
UiUnifi ControllerAll versions
W1.FiHostapd< 2.0.0
AsusRt-N11All versions
BroadcomAdslAll versions
CanonSelphy Cp1200All versions
CiscoWap131All versions
CiscoWap150All versions
CiscoWap351All versions
DlinkDvg-N5412spAll versions
DellB1165nfwAll versions
EpsonEp-101All versions
EpsonEw-M970a3tAll versions
EpsonM571tAll versions
EpsonXp-100All versions
EpsonXp-2101All versions
EpsonXp-2105All versions
EpsonXp-241All versions
EpsonXp-320All versions
EpsonXp-330All versions
EpsonXp-340All versions
EpsonXp-4100All versions
EpsonXp-4105All versions
EpsonXp-440All versions
EpsonXp-620All versions
EpsonXp-630All versions
EpsonXp-702All versions
EpsonXp-8500All versions
EpsonXp-8600All versions
EpsonXp-960All versions
EpsonXp-970All versions
Hp5020 Z4a69aAll versions
Hp5030 M2u92bAll versions
Hp5030 Z4a70aAll versions
Hp5034 Z4a74aAll versions
Hp5660 F8b04aAll versions
HpDeskjet Ink Advantage 3456 A9t84cAll versions
HpDeskjet Ink Advantage 3545 A9t81aAll versions
HpDeskjet Ink Advantage 3545 A9t81cAll versions
HpDeskjet Ink Advantage 3545 A9t83bAll versions
HpDeskjet Ink Advantage 3546 A9t82aAll versions
HpDeskjet Ink Advantage 3548 A9t81bAll versions
HpDeskjet Ink Advantage 4515All versions
HpDeskjet Ink Advantage 4518All versions
HpDeskjet Ink Advantage 4535 F0v64aAll versions
HpDeskjet Ink Advantage 4535 F0v64bAll versions
HpDeskjet Ink Advantage 4535 F0v64cAll versions
HpDeskjet Ink Advantage 4536 F0v65aAll versions
HpDeskjet Ink Advantage 4538 F0v66bAll versions
HpDeskjet Ink Advantage 4675 F1h97aAll versions
HpDeskjet Ink Advantage 4675 F1h97bAll versions

Showing 50 of 219 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-12695?
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
How severe is CVE-2020-12695?
CVE-2020-12695 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 15.19% probability of exploitation in the next 30 days.
How do I fix CVE-2020-12695?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-12695?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST