VulnerabilityModified
CVE-2021-31718
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
HIGH 8.8EPSS 0.96%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA endpoints), leading to remote code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.96% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346
- Affected
- npupnp project/npupnp
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/04/25/2Mailing List, Third Party Advisory
- https://framagit.org/medoc92/npupnpThird Party Advisory
- https://www.lesbonscomptes.com/upmpdcli/npupnp-doc/libnpupnp.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/25/2Mailing List, Third Party Advisory
- https://framagit.org/medoc92/npupnpThird Party Advisory
- https://www.lesbonscomptes.com/upmpdcli/npupnp-doc/libnpupnp.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.