High severity7.5NVD Advisory· Published Jun 8, 2020· Updated Jun 17, 2026
CVE-2020-12695
CVE-2020-12695
Description
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- Open Connectivity Foundation/UPnP specificationdescription
- Range: <2020-04-17
- osv-coords13 versionspkg:rpm/almalinux/gssdppkg:rpm/almalinux/gssdp-develpkg:rpm/almalinux/gssdp-docspkg:rpm/almalinux/gupnp-develpkg:rpm/opensuse/gupnp&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/hostapd&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/hostapd&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/minidlna&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/minidlna&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/minidlna&distro=openSUSE%20Tumbleweedpkg:rpm/suse/hostapd&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/minidlna&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/minidlna&distro=SUSE%20Package%20Hub%2015%20SP2
< 1.0.5-1.el8+ 12 more
- (no CPE)range: < 1.0.5-1.el8
- (no CPE)range: < 1.0.5-1.el8
- (no CPE)range: < 1.0.5-1.el8
- (no CPE)range: < 1.0.6-1.el8
- (no CPE)range: < 1.2.7-2.2
- (no CPE)range: < 2.9-lp152.2.3.1
- (no CPE)range: < 2.9-6.2
- (no CPE)range: < 1.3.0-lp151.3.3.1
- (no CPE)range: < 1.3.0-lp152.4.3.1
- (no CPE)range: < 1.3.0-2.7
- (no CPE)range: < 2.9-bp152.2.3.1
- (no CPE)range: < 1.3.0-bp151.2.3.1
- (no CPE)range: < 1.3.0-bp152.4.3.1
Patches
Vulnerability mechanics
References
15- packetstormsecurity.com/files/158051/CallStranger-UPnP-Vulnerability-Checker.htmlnvdThird Party AdvisoryVDB Entry
- www.openwall.com/lists/oss-security/2020/06/08/2nvdMailing ListThird Party Advisory
- corelight.blog/2020/06/10/detecting-the-new-callstranger-upnp-vulnerability-with-zeek/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/08/msg00011.htmlnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/08/msg00013.htmlnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/12/msg00017.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3SHL4LOFGHJ3DIXSUIQELGVBDJ7V7LB/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZDWHKGN3LMGSUEOAAVAMOD3IUIPJVOJ/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQEYVY4D7LASH6AI4WK3IK2QBFHHF3Q2/nvdMailing ListThird Party Advisory
- usn.ubuntu.com/4494-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4806nvdThird Party Advisory
- www.debian.org/security/2021/dsa-4898nvdThird Party Advisory
- www.kb.cert.org/vuls/id/339275nvdThird Party AdvisoryUS Government Resource
- www.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-ofnvdThird Party Advisory
- www.callstranger.comnvdBroken Link
News mentions
0No linked articles in our index yet.