UPnP Internet Gateway Device (IGD) Port Mapping Listing
Medium Nessus Plugin ID 94048
SynopsisIt was possible to list the port mappings created via UPnP IGD on the
DescriptionAccording to its UPnP data, the remote device is a NAT router that
supports the Internet Gateway Device (IGD) Standardized Device Control
Protocol. Nessus was able to list 'port mappings' that redirect ports
from the device's external interface to the scanner address.
An unauthenticated, remote attacker can exploit this issue (e.g., via
device's firewall. An unauthenticated, adjacent attacker has
unrestricted access to this interface.
SolutionDisable IGD or restrict access to trusted networks.