5.3

CVE-2018-12227

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not identified, then a 401 unauthorized response is sent. This vulnerability just discloses which requests hit a defined endpoint. The ACL rules cannot be bypassed to gain access to the disclosed endpoints.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Asterisk Version >= 13.0.0 < 13.21.1
Digium ≫ Asterisk Version > 14.0.0 < 14.7.7
Digium ≫ Asterisk Version >= 15.0.0 < 15.4.1
Digium ≫ Certified Asterisk Version 13.18 Update cert1
Digium ≫ Certified Asterisk Version 13.18 Update cert2
Digium ≫ Certified Asterisk Version 13.18 Update cert3
Digium ≫ Certified Asterisk Version 13.21 Update cert1
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.49% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://security.gentoo.org/glsa/201811-11
Third Party Advisory
https://www.debian.org/security/2018/dsa-4320
Third Party Advisory
http://downloads.asterisk.org/pub/security/AST-2018-008.html
Vendor Advisory
http://www.securityfocus.com/bid/104455
Third Party Advisory
VDB Entry
https://issues.asterisk.org/jira/browse/ASTERISK-27818
Patch
Vendor Advisory