CVE-2020-24376

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/09/2020
Last modified:
13/11/2020

Description

A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:free:freebox_revolution_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_revolution:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_mini_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_mini:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_one_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_one:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_delta_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_delta:-:*:*:*:*:*:*:*
cpe:2.3:o:free:freebox_pop_firmware:*:*:*:*:*:*:*:* 4.2.3 (excluding)
cpe:2.3:h:free:freebox_pop:-:*:*:*:*:*:*:*