CVE-2008-1332Asterisk vulnerability

CWE-2646 documents6 sources
Severity
8.8HIGHNVD
EPSS
1.2%
top 20.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 1

Description

Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 revision 109393; and s800i 1.0.x before 1.1.0.2; allows remote attackers to access the SIP channel driver via a crafted From header.

CVSS vector

AV:N/AC:M/C:C/I:C/A:NExploitability: 8.6 | Impact: 9.2

Affected Packages8 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p49c-76rr-74ww: Unspecified vulnerability in Asterisk Open Source 12022-05-01
OSV
CVE-2008-1332: Unspecified vulnerability in Asterisk Open Source 12008-03-20

📋Vendor Advisories

2
Debian
CVE-2008-1332: asterisk - Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x bef...2008
Red Hat
asterisk: Unauthenticated calls allowed from SIP channel driver (AST-2008-003)

💬Community

1
Bugzilla
CVE-2008-1332 asterisk: Unauthenticated calls allowed from SIP channel driver (AST-2008-003)2008-03-19
CVE-2008-1332 — Debian Asterisk vulnerability | cvebase