HIGH🇵🇱 Wersja polska

CVE-2023-49786

CVSS 7.5v3.1pub. 2023-12-14upd. 2024-11-21

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. Commit d7d7764cb07c8a1872804321302ef93bf62cba05 contains a fix, which is part of versions 18.20.1, 20.5.1, 21.0.1, amd 18.9-cert6.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Digium Asterisk

    APP
    Digium
    21.0.0< 18.20.119.0.0 – 20.5.1 (excl.)
  • Sangoma Certified Asterisk

    APP
    Sangoma
    13.13.016.8.018.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSRace Condition
CWE
References

Related vulnerabilities

CVE-2022-26499CRITICAL9.1PL ✓same product

SSRF w Asterisk przez nagłówek Identity w mechanizmie STIR/SHAKEN

CVE-2022-26651CRITICAL9.8PL ✓same product

SQL Injection w module func_odbc systemu Asterisk (AST-2022-003)

CVE-2017-14100CRITICAL9.8PL ✓same product

Command injection w Asterisk przez pole caller-id w module app_minivm

CVE-2025-1131HIGH7.0same product

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolk...

CVE-2025-47779HIGH7.7same product

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4...