- Description
- The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and the remote SIP server challenges for authentication of the resulting OPTIONS request," allows remote attackers to cause a denial of service (crash) via a PJSIP endpoint that does not have an associated outgoing request.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:N/A:P
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:asterisk:12.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B446105E-6C8E-495A-BF83-A33CB33485A5"
},
{
"criteria": "cpe:2.3:a:digium:asterisk:12.1.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3DE062D-4E87-4691-A664-D9E7C02036EB"
},
{
"criteria": "cpe:2.3:a:digium:asterisk:12.1.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3B4D6D24-A718-4962-AD4E-F19AFB03BFF4"
},
{
"criteria": "cpe:2.3:a:digium:asterisk:12.1.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE2F0D0D-761C-4338-93F0-506E94E57000"
},
{
"criteria": "cpe:2.3:a:digium:asterisk:12.1.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D38DFCA-E357-4A28-8F03-FDADF40A5185"
}
],
"operator": "OR"
}
]
}
]