CVE-2021-29462
HIGHpupnp < 1.14.6 - DNS Rebinding Attack via Missing Host Header Validation
Title source: llmDescription
The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/pupnp/pupnp/security/advisories/GHSA-6hqq-w3jq-9fhg
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/04/20/4
Scores
CVSS v3
7.6
EPSS
0.0063
EPSS Percentile
45.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Details
CWE
CWE-345
CWE-20
Status
published
Products (1)
pupnp_project/pupnp
< 1.14.6
Published
Apr 20, 2021
Tracked Since
Feb 18, 2026