CVE-2021-33516
gupnp: allows DNS rebinding which could result in tricking browser into triggering actions against local UPnP services
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
Se detectó un problema en GUPnP versiones anteriores a 1.0.7 y 1.1.x y versiones 1.2.x anteriores a 1.2.5. Permite el reenlace de DNS. Un servidor web remoto puede explotar esta vulnerabilidad para engañar al navegador de la víctima para desencadenar acciones contra los servicios UPnP locales implementados usando esta biblioteca. Dependiendo del servicio afectado, esto podría usarse para exfiltración de datos, manipulación de datos, etc
A flaw was found in gupnp. DNS rebinding can occur when a victim's browser is used by a remote web server to trigger actions against local UPnP services including data exfiltration, data tempering, and other exploits. The highest threat from this vulnerability is to data confidentiality and integrity.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-24 CVE Reserved
- 2021-05-24 CVE Published
- 2024-02-07 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://discourse.gnome.org/t/security-relevant-releases-for-gupnp-issue-cve-2021-33516/6536 | 2021-05-28 |
URL | Date | SRC |
---|---|---|
https://gitlab.gnome.org/GNOME/gupnp/-/issues/24 | 2021-05-28 | |
https://access.redhat.com/security/cve/CVE-2021-33516 | 2021-06-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1964091 | 2021-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Gupnp Search vendor "Gnome" for product "Gupnp" | < 1.0.7 Search vendor "Gnome" for product "Gupnp" and version " < 1.0.7" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gupnp Search vendor "Gnome" for product "Gupnp" | >= 1.1.0 < 1.2.5 Search vendor "Gnome" for product "Gupnp" and version " >= 1.1.0 < 1.2.5" | - |
Affected
|