7.5
CVSSv3

CVE-2021-26712

Published: 18/02/2021 Updated: 24/02/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated malicious user to prematurely terminate secure calls by replaying SRTP packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk

digium certified asterisk 16.8

Mailing Lists

Asterisk Project Security Advisory - AST-2021-003 Product Asterisk Summary Remote attacker could prematurely tear down SRTP calls Nature of Advisory Denial of Service ...