Breaking News

ZOTAC to Showcase New Graphics Card Models, Handheld Consoles, and AI-accelerated Systems at COMPUTEX 2025 ZHIYUN Launches CINEPEER SMOOTH 5E Mainstream Smartphone Gimbal xMEMS Unveils Sycamore-W – The World’s Thinnest Speaker Engineered for Smart Watches and Fitness Bands Samsung announces Galaxy S25 Edge DJI announces Mavic 4 Pro

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Homeland Security Says UPnP Poses Risks

Homeland Security Says UPnP Poses Risks

Enterprise & IT Jan 29,2013 0

The U.S. government is warning to disable UPnP, a common networking feature, after bugs have left millions of hardware devices vulnerable to attacks by hackers and malware. The Department of Homeland Security urged computer users on Tuesday to disable Universal Plug and Play (UPnP), a set of network protocols designed to support automatic discovery and service configuration.

The security bugs were initially brought to the attention of the government by computer security company Rapid7, in Boston, which released a report on the problem on Tuesday. The company said it discovered between 40 million and 50 million devices that were vulnerable to attack due to problems that the firm's researchers have identified with the UPnP standard.

According to Rapid7, the two most commonly used UPnP software libraries both contained remotely exploitable vulnerabilities. In the case of the Portable UPnP SDK, over 23 million IPs are vulnerable to remote code execution through a single UDP packet. The company identified over 6,900 product versions that were vulnerable through UPnP. This list encompasses over 1,500 vendors.

The vulnerabilities Rapid7 identified in the Portable UPnP SDK have been fixed as of version 1.6.18 (released today), but it will take a long time before each of the application and device vendors incorporate this patch into their products.

The flaws could allow hackers to access files, steal passwords, take full control over PCs as well as remotely access devices such as webcams, printers and security systems.

Rapid7 has released a free tool that can identify exposed UPnP endpoints in your network and flag which of those may remotely exploitable through recently discovered vulnerabilities.

Tags:
Previous Post
BlackBerry 10: RIM's Last Hope To Apple And Samsung
Next Post
Get Ready For Crysis 3 beta With New AMD Catalyst Drivers

Related Posts

Latest News

ZOTAC to Showcase New Graphics Card Models, Handheld Consoles, and AI-accelerated Systems at COMPUTEX 2025
GPUs

ZOTAC to Showcase New Graphics Card Models, Handheld Consoles, and AI-accelerated Systems at COMPUTEX 2025

ZHIYUN Launches CINEPEER SMOOTH 5E Mainstream Smartphone Gimbal
Cameras

ZHIYUN Launches CINEPEER SMOOTH 5E Mainstream Smartphone Gimbal

xMEMS Unveils Sycamore-W – The World’s Thinnest Speaker Engineered for Smart Watches and Fitness Bands
Enterprise & IT

xMEMS Unveils Sycamore-W – The World’s Thinnest Speaker Engineered for Smart Watches and Fitness Bands

Samsung announces Galaxy S25 Edge
Smartphones

Samsung announces Galaxy S25 Edge

DJI announces Mavic 4 Pro
Drones

DJI announces Mavic 4 Pro

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Rock 5

be quiet! Dark Rock 5

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed