CVE-2014-4047 — Asterisk vulnerability
7 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
3.0%
top 13.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 17
Latest updateMay 14
Description
Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2014-4047: asterisk - Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before...↗2014
💬Community
3Bugzilla▶
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007)↗2014-06-13
Bugzilla▶
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007) [epel-6]↗2014-06-13
Bugzilla▶
CVE-2014-4047 asterisk: DoS due to Exhaustion of Allowed Concurrent HTTP Connections (AST-2014-007) [fedora-all]↗2014-06-13