UPnP Internet Gateway Device (IGD) Port Mapping Manipulation
Medium Nessus Plugin ID 35707
SynopsisIt was possible to add port redirections to the remote router.
DescriptionAccording to its UPnP data, the remote device is a NAT router that
supports the Internet Gateway Device (IGD) Standardized Device Control
Protocol. Nessus was able to add 'port mappings' that redirect ports
from the device's external interface to the scanner address.
An unauthenticated, remote attacker can exploit this issue (e.g., via
device's firewall. An unauthenticated, adjacent attacker has
unrestricted access to this interface.
SolutionDisable IGD or restrict access to trusted networks.