4
CVSSv2

CVE-2021-31878

Published: 30/07/2021 Updated: 07/08/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in PJSIP in Asterisk prior to 16.19.1 and prior to 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digium asterisk 16.17.0

digium asterisk 16.18.0

digium asterisk 16.19.0

digium asterisk 18.3.0

digium asterisk 18.4.0

digium asterisk 18.5.0

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> AST-2021-007: Remote Crash Vulnerability in PJSIP channel driver <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...