5
CVE-2014-8412
- EPSS 2.73%
- Veröffentlicht 24.11.2014 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8.28 before 1.8.28-cert3 and 11.6 before 11.6-cert8 allows remote attackers to bypass the ACL restrictions via a packet with a source IP that does not share the address family as the first ACL entry.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Certified Asterisk Version 1.8.28 Update cert1 SwEdition lts
Digium ≫ Certified Asterisk Version 1.8.28 Update cert2 SwEdition lts
Digium ≫ Certified Asterisk Version 1.8.28.0 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert1 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert2 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert3 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert4 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert5 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert6 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6 Update cert7 SwEdition lts
Digium ≫ Certified Asterisk Version 11.6.0 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.73% | 0.842 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://downloads.asterisk.org/pub/security/AST-2014-012.html