![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2021-33516 |
Description: | An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.844959 1.3.6.1.4.1.25623.1.0.853927 1.3.6.1.4.1.25623.1.1.10.2021.0321 1.3.6.1.4.1.25623.1.1.2.2022.2613 1.3.6.1.4.1.25623.1.1.2.2022.1891 1.3.6.1.4.1.25623.1.1.4.2021.2153.1 1.3.6.1.4.1.25623.1.1.2.2022.1568 1.3.6.1.4.1.25623.1.0.853888 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2021-33516 https://discourse.gnome.org/t/security-relevant-releases-for-gupnp-issue-cve-2021-33516/6536 https://gitlab.gnome.org/GNOME/gupnp/-/issues/24 |