4.3
CVE-2008-1897
- EPSS 3.48%
- Veröffentlicht 23.04.2008 16:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asterisk ≫ Asterisk Appliance Developer Kit Version0.2
Asterisk ≫ Asterisk Appliance Developer Kit Version0.3
Asterisk ≫ Asterisk Appliance Developer Kit Version0.4
Asterisk ≫ Asterisk Appliance Developer Kit Version0.5
Asterisk ≫ Asterisk Appliance Developer Kit Version0.6
Asterisk ≫ Asterisk Appliance Developer Kit Version0.6.0
Asterisk ≫ Asterisk Appliance Developer Kit Version0.7
Asterisk ≫ Asterisk Appliance Developer Kit Version0.8
Asterisk ≫ Asterisk Business Edition Version <= b.2.5.1
Asterisk ≫ Asterisk Business Edition Version <= c1.8.0
Asterisk ≫ Asterisk Business Edition Versiona
Asterisk ≫ Asterisk Business Edition Versionb.1.3.2
Asterisk ≫ Asterisk Business Edition Versionb.1.3.3
Asterisk ≫ Asterisk Business Edition Versionb.2.2.0
Asterisk ≫ Asterisk Business Edition Versionb.2.2.1
Asterisk ≫ Asterisk Business Edition Versionb.2.3.1
Asterisk ≫ Asterisk Business Edition Versionb.2.3.2
Asterisk ≫ Asterisk Business Edition Versionb.2.3.3
Asterisk ≫ Asterisk Business Edition Versionb.2.3.4
Asterisk ≫ Asterisk Business Edition Versionb.2.3.6
Asterisk ≫ Asterisk Business Edition Versionb.2.5.0
Asterisk ≫ Asterisk Business Edition Versionc.1.0 Updatebeta7
Asterisk ≫ Asterisk Business Edition Versionc.1.0 Updatebeta8
Asterisk ≫ Asterisk Business Edition Versionc.1.6
Asterisk ≫ Asterisk Business Edition Versionc.1.6.1
Asterisk ≫ Asterisk Business Edition Versionc.1.6.2
Asterisk ≫ Asterisknow Version <= 1.0.2
Asterisk ≫ Asterisknow Version1.0
Asterisk ≫ Asterisknow Version1.0.1
Asterisk ≫ Open Source Version <= 1.2.27
Asterisk ≫ Open Source Version <= 1.4.19
Asterisk ≫ Open Source Version1.0
Asterisk ≫ Open Source Version1.0 Updaterc1
Asterisk ≫ Open Source Version1.0 Updaterc2
Asterisk ≫ Open Source Version1.0.0
Asterisk ≫ Open Source Version1.0.1
Asterisk ≫ Open Source Version1.0.2
Asterisk ≫ Open Source Version1.0.3
Asterisk ≫ Open Source Version1.0.3.4
Asterisk ≫ Open Source Version1.0.4
Asterisk ≫ Open Source Version1.0.5
Asterisk ≫ Open Source Version1.0.6
Asterisk ≫ Open Source Version1.0.7
Asterisk ≫ Open Source Version1.0.8
Asterisk ≫ Open Source Version1.0.9
Asterisk ≫ Open Source Version1.0.11
Asterisk ≫ Open Source Version1.0.11 Updatepatch
Asterisk ≫ Open Source Version1.0.11.1
Asterisk ≫ Open Source Version1.0.11.1 Updatepatch
Asterisk ≫ Open Source Version1.0.12
Asterisk ≫ Open Source Version1.0.12 Updatepatch
Asterisk ≫ Open Source Version1.2.0
Asterisk ≫ Open Source Version1.2.0 Updatebeta1
Asterisk ≫ Open Source Version1.2.0 Updatebeta2
Asterisk ≫ Open Source Version1.2.0 Updaterc1
Asterisk ≫ Open Source Version1.2.0 Updaterc2
Asterisk ≫ Open Source Version1.2.1
Asterisk ≫ Open Source Version1.2.2
Asterisk ≫ Open Source Version1.2.2 Updatenetsec
Asterisk ≫ Open Source Version1.2.3
Asterisk ≫ Open Source Version1.2.3 Updatenetsec
Asterisk ≫ Open Source Version1.2.4
Asterisk ≫ Open Source Version1.2.4 Updatenetsec
Asterisk ≫ Open Source Version1.2.5
Asterisk ≫ Open Source Version1.2.5 Updatenetsec
Asterisk ≫ Open Source Version1.2.6
Asterisk ≫ Open Source Version1.2.6 Updatenetsec
Asterisk ≫ Open Source Version1.2.7
Asterisk ≫ Open Source Version1.2.7 Updatenetsec
Asterisk ≫ Open Source Version1.2.7.1
Asterisk ≫ Open Source Version1.2.7.1 Updatenetsec
Asterisk ≫ Open Source Version1.2.8
Asterisk ≫ Open Source Version1.2.8 Updatenetsec
Asterisk ≫ Open Source Version1.2.9
Asterisk ≫ Open Source Version1.2.9.1
Asterisk ≫ Open Source Version1.2.9.1 Updatenetsec
Asterisk ≫ Open Source Version1.2.10
Asterisk ≫ Open Source Version1.2.10 Updatenetsec
Asterisk ≫ Open Source Version1.2.11
Asterisk ≫ Open Source Version1.2.11 Updatenetsec
Asterisk ≫ Open Source Version1.2.12
Asterisk ≫ Open Source Version1.2.12 Updatenetsec
Asterisk ≫ Open Source Version1.2.12.1
Asterisk ≫ Open Source Version1.2.12.1 Updatenetsec
Asterisk ≫ Open Source Version1.2.13
Asterisk ≫ Open Source Version1.2.13 Updatenetsec
Asterisk ≫ Open Source Version1.2.14
Asterisk ≫ Open Source Version1.2.14 Updatenetsec
Asterisk ≫ Open Source Version1.2.15
Asterisk ≫ Open Source Version1.2.15 Updatenetsec
Asterisk ≫ Open Source Version1.2.16
Asterisk ≫ Open Source Version1.2.16 Updatenetsec
Asterisk ≫ Open Source Version1.2.17
Asterisk ≫ Open Source Version1.2.17 Updatenetsec
Asterisk ≫ Open Source Version1.2.18
Asterisk ≫ Open Source Version1.2.18 Updatenetsec
Asterisk ≫ Open Source Version1.2.19
Asterisk ≫ Open Source Version1.2.19 Updatenetsec
Asterisk ≫ Open Source Version1.2.20
Asterisk ≫ Open Source Version1.2.20 Updatenetsec
Asterisk ≫ Open Source Version1.2.21
Asterisk ≫ Open Source Version1.2.21 Updatenetsec
Asterisk ≫ Open Source Version1.2.21.1
Asterisk ≫ Open Source Version1.2.21.1 Updatenetsec
Asterisk ≫ Open Source Version1.2.22
Asterisk ≫ Open Source Version1.2.22 Updatenetsec
Asterisk ≫ Open Source Version1.2.23
Asterisk ≫ Open Source Version1.2.23 Updatenetsec
Asterisk ≫ Open Source Version1.2.24
Asterisk ≫ Open Source Version1.2.24 Updatenetsec
Asterisk ≫ Open Source Version1.2.25
Asterisk ≫ Open Source Version1.2.25 Updatenetsec
Asterisk ≫ Open Source Version1.2.26
Asterisk ≫ Open Source Version1.2.26 Updatenetsec
Asterisk ≫ Open Source Version1.2.26.1
Asterisk ≫ Open Source Version1.2.26.1 Updatenetsec
Asterisk ≫ Open Source Version1.2.26.2
Asterisk ≫ Open Source Version1.2.26.2 Updatenetsec
Asterisk ≫ Open Source Version1.4.0
Asterisk ≫ Open Source Version1.4.0 Updatebeta2
Asterisk ≫ Open Source Version1.4.0 Updatebeta3
Asterisk ≫ Open Source Version1.4.0 Updatebeta4
Asterisk ≫ Open Source Version1.4.1
Asterisk ≫ Open Source Version1.4.10
Asterisk ≫ Open Source Version1.4.10.1
Asterisk ≫ Open Source Version1.4.11
Asterisk ≫ Open Source Version1.4.12
Asterisk ≫ Open Source Version1.4.12.1
Asterisk ≫ Open Source Version1.4.13
Asterisk ≫ Open Source Version1.4.14
Asterisk ≫ Open Source Version1.4.15
Asterisk ≫ Open Source Version1.4.16
Asterisk ≫ Open Source Version1.4.16.1
Asterisk ≫ Open Source Version1.4.16.2
Asterisk ≫ Open Source Version1.4.17
Asterisk ≫ Open Source Version1.4.18
Asterisk ≫ Open Source Version1.4.18.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.48% | 0.871 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.