Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-0230Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Miniupnpd

Severity
10.0CRITICALNVD
NVD7.8
EPSS
65.9%
top 1.48%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 31
Latest updateMay 17

Description

Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

4
GHSA
GHSA-rhgq-m6r3-xf46: Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 12022-05-17
GHSA
GHSA-fp8r-qhv9-2hqm: The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 12022-05-17
GHSA
GHSA-v9m6-5wqp-m9mc: Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 12022-05-05
VulnCheck
miniupnp_project miniupnpd Improper Restriction of Operations within the Bounds of a Memory Buffer2013

💥Exploits & PoCs

5
Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service2015-07-07
Exploit-DB
MiniUPnPd 1.0 (MIPS) - Remote Stack Overflow Remote Code Execution for AirTies RT Series2015-04-27
Exploit-DB
MiniUPnPd 1.0 - Remote Stack Buffer Overflow Remote Code Execution (Metasploit)2013-06-05
Metasploit
UPnP SSDP M-SEARCH Information Discovery
Metasploit
MiniUPnPd 1.0 Stack Buffer Overflow Remote Code Execution

📋Vendor Advisories

3
Debian
CVE-2013-0230: miniupnpd - Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction ...2013
Debian
CVE-2013-1462: miniupnpd - Integer signedness error in the ExecuteSoapAction function in the SOAPAction han...2013
Debian
CVE-2013-1461: miniupnpd - The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in ...2013

🕵️Threat Intelligence

7
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
UPnP-enabled Home Devices and Vulnerabilities2019-03-06
Trendmicro
VPNFilter-affected Devices Still Riddled with 19 Bugs2018-07-13

💬Community

1
Bugzilla
CVE-2012-5629 JBoss: allows empty password to authenticate against LDAP2012-12-10