cbcvebase.
CVE-2015-1558
published 2015-02-09

CVE-2015-1558: Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote…

PriorityP417low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
3.03%
85.8th percentile
Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianasterisk< asterisk 1:13.1.0~dfsg-1.1 (bullseye)asterisk 1:13.1.0~dfsg-1.1 (bullseye)
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk
digiumasterisk>= 0 < 1:13.1.0~dfsg-1.11:13.1.0~dfsg-1.1

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.