CVE-2013-0230 describes a critical stack-based buffer overflow in MiniUPnPd 1.0, specifically within the ExecuteSoapAction function of its HTTP service, affecting miniupnp_project miniupnpd. This vulnerability carries a CVSS score of 10.0, indicating a severe risk where unauthenticated remote attackers can execute arbitrary code with low attack complexity. Exploit code is publicly available, including Metasploit modules and several ExploitDB entries, demonstrating its ease of exploitation. While not listed in KEV, its high EPSS and FAUCET scores, along with community discussion and media coverage, highlight its significant potential for impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:miniupnp_project:miniupnpd:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.