HomeSecurityCallStranger vulnerability bypasses security solutions and scans LANs

CallStranger vulnerability bypasses security solutions and scans LANs

CallStranger vulnerability

A serious vulnerability has been discovered in a core protocol found in almost all Internet of Things (IoT) devices. The vulnerability, called CallStranger, allows attackers to hack into smart devices to launch DDoS attacks and bypass security to scan internal network a victim's. This hackers to gain access to areas they normally shouldn't.

CallStranger vulnerability affects UPnP

The CallStranger vulnerability is said to affect UpnP (Universal Plug and Play), a set of protocols found in most smart devices.

UPnP allows devices to "see" each other on local networks and create connections for easy exchange of data, configurations, etc.

UPnP has been around since the early 2000s, but since 2016, its development has been managed by the Open Connectivity Foundation (OCF).

CallStranger vulnerability bypasses security solutions and scans LANs

Technical details about the CallStranger vulnerability

In December 2019, a security named Yunus Çadircifound a flaw in this extremely widespread technology.

Çadirci says that an attacker can send TCP packets to a remote device that contain a malformed callback header value in UPnP's SUBSCRIBE function.

This header can be used by malicious hackers to exploit any smart device that remains connected to the Internet and supports UPnP protocols (e.g. security cameras, DVRs, printers, routers, and more).

In a CallStranger attack, the attacker targets the internet-facing interface of the device, but executes code on the device's UPnP, which typically only runs on internal ports (inside the LAN).

Çadirci says that attackers could use the CallStranger vulnerability to successfully bypass network security systems and firewalls to scan a company 's internal networks .

In addition, other attacks can be carried out, such as DdoS. This also includes data theft, as the attacker gains access to data on the vulnerable device.

Fixing the vulnerability may take some time

Çadirci said he notified OCF of the vulnerability. The company updated the UPnP protocols. The updates were released on April 17, 2020.

However, Çadirci said: “Because this is a protocol vulnerability, it may take a long time for vendors to provide updates,” suggesting that firmware patches may be delayed.

The researcher published a site containing basic advice on how businesses can block potential exploitation attempts.

Additionally, Çadirci published proof-of-concept scripts that companies can use to determine whether their smart devices are vulnerable to the CallStranger vulnerability.

The CallStranger vulnerability is also known as CVE-2020-12695. There are currently around 5.45 million UPnP-enabled devices connected to the internet, meaning that many hackers will find the vulnerability ideal for carrying out attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS