Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-3263Improper Restriction of Operations within the Bounds of a Memory Buffer in Asterisk

Severity
7.8HIGHNVD
EPSS
36.1%
top 2.89%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 22
Latest updateMay 2

Description

The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (call-number exhaustion and CPU consumption) by quickly sending a large number of IAX2 (IAX) POKE requests.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages8 packages

NVDasterisk/opensource5 versions+4
NVDasterisk/open_source87 versions+86
NVDasterisk/appliance_s800i1.3, 1.3.0.2+1
debiandebian/asterisk< asterisk 1:1.6.2.0~dfsg~beta3-1 (bullseye)+1
Debiansangoma/asterisk< 1:1.6.2.0~dfsg~beta3-1

🔴Vulnerability Details

4
GHSA
GHSA-qm3m-5rgr-2hq8: The IAX2 protocol implementation in Asterisk Open Source 12022-05-02
GHSA
GHSA-w3xv-vhr5-qfqw: The IAX2 protocol implementation in Asterisk Open Source 12022-05-01
OSV
CVE-2009-2346: The IAX2 protocol implementation in Asterisk Open Source 12009-09-08
OSV
CVE-2008-3263: The IAX2 protocol implementation in Asterisk Open Source 12008-07-22

💥Exploits & PoCs

1
Exploit-DB
Asterisk 1.6 IAX - 'POKE' Requests Remote Denial of Service2008-07-21

📋Vendor Advisories

3
Red Hat
asterisk: IAX2 DoS vulnerability (AST-2009-006)2009-09-03
Debian
CVE-2009-2346: asterisk - The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1....2009
Debian
CVE-2008-3263: asterisk - The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2...2008

💬Community

1
Bugzilla
CVE-2009-2346 asterisk: IAX2 DoS vulnerability (AST-2009-006)2009-09-04
CVE-2008-3263 — Debian Asterisk vulnerability | cvebase