5

CVE-2014-8414

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of service (channel hang and memory consumption) by causing transitions to be delayed, which triggers a state change from hung up to waiting for media.

Data is provided by the National Vulnerability Database (NVD)
DigiumAsterisk SwEditionlts Version <= 11.14.0
DigiumCertified Asterisk Version11.6 Updatecert1 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert2 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert3 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert4 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert5 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert6 SwEditionlts
DigiumCertified Asterisk Version11.6 Updatecert7 SwEditionlts
DigiumCertified Asterisk Version11.6.0 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.9% 0.825
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P