CVE-2021-29462

HIGH

pupnp < 1.14.6 - DNS Rebinding Attack via Missing Host Header Validation

Title source: llm
STIX 2.1

Description

The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/04/20/4

Scores

CVSS v3 7.6
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Details

CWE
CWE-345 CWE-20
Status published
Products (1)
pupnp_project/pupnp < 1.14.6
Published Apr 20, 2021
Tracked Since Feb 18, 2026