Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2017-14099 (GCVE-0-2017-14099)
Vulnerability from cvelistv5 – Published: 2017-09-02 16:00 – Updated: 2024-08-05 19:20- n/a
| URL | Tags | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||||||||
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T19:20:39.853Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "GLSA-201710-29",
"tags": [
"vendor-advisory",
"x_refsource_GENTOO",
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"name": "DSA-3964",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN",
"x_transferred"
],
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"name": "1039251",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK",
"x_transferred"
],
"url": "http://www.securitytracker.com/id/1039251"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://bugs.debian.org/873907"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://rtpbleed.com"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2017-09-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-11-03T18:57:01.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "GLSA-201710-29",
"tags": [
"vendor-advisory",
"x_refsource_GENTOO"
],
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"name": "DSA-3964",
"tags": [
"vendor-advisory",
"x_refsource_DEBIAN"
],
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"name": "1039251",
"tags": [
"vdb-entry",
"x_refsource_SECTRACK"
],
"url": "http://www.securitytracker.com/id/1039251"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://bugs.debian.org/873907"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "https://rtpbleed.com"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2017-14099",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "GLSA-201710-29",
"refsource": "GENTOO",
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"name": "https://issues.asterisk.org/jira/browse/ASTERISK-27013",
"refsource": "CONFIRM",
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"name": "DSA-3964",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"name": "1039251",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1039251"
},
{
"name": "http://downloads.asterisk.org/pub/security/AST-2017-005.html",
"refsource": "CONFIRM",
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"name": "https://bugs.debian.org/873907",
"refsource": "CONFIRM",
"url": "https://bugs.debian.org/873907"
},
{
"name": "https://rtpbleed.com",
"refsource": "MISC",
"url": "https://rtpbleed.com"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2017-14099",
"datePublished": "2017-09-02T16:00:00.000Z",
"dateReserved": "2017-08-31T00:00:00.000Z",
"dateUpdated": "2024-08-05T19:20:39.853Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CERTFR-2017-AVI-281
Vulnerability from certfr_avis - Published: 2017-09-01 - Updated: 2017-09-01
De multiples vulnérabilités ont été corrigées dans Asterisk. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
None| Vendor | Product | Description | ||
|---|---|---|---|---|
| Asterisk | Certified Asterisk | Certified Asterisk versions antérieures à 11.6-cert17 et 13.13-cert5 | ||
| Asterisk | Asterisk | Asterisk Open Source versions antérieures à 11.25.2, 13.17.1 et 14.6.1 |
| Title | Publication Time | Tags | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Certified Asterisk versions ant\u00e9rieures \u00e0 11.6-cert17 et 13.13-cert5",
"product": {
"name": "Certified Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
},
{
"description": "Asterisk Open Source versions ant\u00e9rieures \u00e0 11.25.2, 13.17.1 et 14.6.1",
"product": {
"name": "Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2017-14099",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14099"
},
{
"name": "CVE-2017-14100",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14100"
},
{
"name": "CVE-2017-14098",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14098"
}
],
"initial_release_date": "2017-09-01T00:00:00",
"last_revision_date": "2017-09-01T00:00:00",
"links": [],
"reference": "CERTFR-2017-AVI-281",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2017-09-01T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans \u003cspan\nclass=\"textit\"\u003eAsterisk\u003c/span\u003e. Elles permettent \u00e0 un attaquant de\nprovoquer une ex\u00e9cution de code arbitraire, un d\u00e9ni de service \u00e0\ndistance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans Asterisk",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Asterisk AST-2017-006 du 31 ao\u00fbt 2017",
"url": "https://downloads.asterisk.org/pub/security/AST-2017-006.html"
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Asterisk AST-2017-007 du 31 ao\u00fbt 2017",
"url": "https://downloads.asterisk.org/pub/security/AST-2017-007.html"
},
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Asterisk AST-2017-005 du 31 ao\u00fbt 2017",
"url": "https://downloads.asterisk.org/pub/security/AST-2017-005.html"
}
]
}
CERTFR-2017-AVI-313
Vulnerability from certfr_avis - Published: 2017-09-20 - Updated: 2017-09-20
Une vulnérabilité a été corrigée dans Asterisk. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
None| Vendor | Product | Description | ||
|---|---|---|---|---|
| Asterisk | Certified Asterisk | Certified Asterisk versions 11.6 antérieures à 11.6-cert18 | ||
| Asterisk | Certified Asterisk | Certified Asterisk versions 13.13 antérieures à 13.13-cert6 | ||
| Asterisk | Asterisk | Asterisk Open Source versions 11.x antérieures à 11.25.3 | ||
| Asterisk | Asterisk | Asterisk Open Source versions 14.x antérieures à 14.6.2 | ||
| Asterisk | Asterisk | Asterisk Open Source versions 13.x antérieures à 13.17.2 |
| Title | Publication Time | Tags | |
|---|---|---|---|
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "Certified Asterisk versions 11.6 ant\u00e9rieures \u00e0 11.6-cert18",
"product": {
"name": "Certified Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
},
{
"description": "Certified Asterisk versions 13.13 ant\u00e9rieures \u00e0 13.13-cert6",
"product": {
"name": "Certified Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
},
{
"description": "Asterisk Open Source versions 11.x ant\u00e9rieures \u00e0 11.25.3",
"product": {
"name": "Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
},
{
"description": "Asterisk Open Source versions 14.x ant\u00e9rieures \u00e0 14.6.2",
"product": {
"name": "Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
},
{
"description": "Asterisk Open Source versions 13.x ant\u00e9rieures \u00e0 13.17.2",
"product": {
"name": "Asterisk",
"vendor": {
"name": "Asterisk",
"scada": false
}
}
}
],
"affected_systems_content": null,
"content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [
{
"name": "CVE-2017-14099",
"url": "https://www.cve.org/CVERecord?id=CVE-2017-14099"
}
],
"initial_release_date": "2017-09-20T00:00:00",
"last_revision_date": "2017-09-20T00:00:00",
"links": [
{
"title": "Bulletin de s\u00e9curit\u00e9 Asterisk AST-2017-008 du 19 septembre 2017",
"url": "http://downloads.asterisk.org/pub/security/AST-2017-008.html"
}
],
"reference": "CERTFR-2017-AVI-313",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2017-09-20T00:00:00.000000"
}
],
"risks": [
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans \u003cspan\nclass=\"textit\"\u003eAsterisk\u003c/span\u003e. Elle permet \u00e0 un attaquant de provoquer\nune atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
"title": "Vuln\u00e9rabilit\u00e9 dans Asterisk",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletin de s\u00e9curit\u00e9 Asterisk AST-2017-008 du 19 septembre 2017",
"url": null
}
]
}
CNVD-2017-30818
Vulnerability from cnvd - Published: 2017-10-20厂商已发布漏洞修复程序,请及时关注更新: http://downloads.asterisk.org/pub/security/AST-2017-005.html
| Name | ['Digium Asterisk 13.*,<13.17.1', 'Digium Asterisk 14.*,<14.6.1', 'Digium Asterisk 11.*,<11.25.2', 'Digium Certified Asterisk 11.*,<11.6-cert17', 'Digium Certified Asterisk 13.*,<13.13-cert5'] |
|---|
{
"cves": {
"cve": {
"cveNumber": "CVE-2017-14099"
}
},
"description": "Digium Asterisk Open Source\u548cCertified Asterisk\u90fd\u662f\u7f8e\u56fdDigium\u516c\u53f8\u7684\u5f00\u6e90\u7535\u8bdd\u4ea4\u6362\u673a\uff08PBX\uff09\u7cfb\u7edf\u8f6f\u4ef6\u3002\u8be5\u8f6f\u4ef6\u652f\u6301\u8bed\u97f3\u4fe1\u7bb1\u3001\u591a\u65b9\u8bed\u97f3\u4f1a\u8bae\u3001\u4ea4\u4e92\u5f0f\u8bed\u97f3\u5e94\u7b54(IVR)\u7b49\u3002\r\n\r\nAsterisk Open Source\u548cCertified Asterisk\u4e2d\u5b58\u5728\u5b89\u5168\u6f0f\u6d1e\u3002\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u52ab\u6301\u76ee\u6807\u5a92\u4f53\u7684\u4f1a\u8bdd\u3002",
"discovererName": "Klaus-Peter Junghanns",
"formalWay": "\u5382\u5546\u5df2\u53d1\u5e03\u6f0f\u6d1e\u4fee\u590d\u7a0b\u5e8f\uff0c\u8bf7\u53ca\u65f6\u5173\u6ce8\u66f4\u65b0\uff1a\r\nhttp://downloads.asterisk.org/pub/security/AST-2017-005.html",
"isEvent": "\u901a\u7528\u8f6f\u786c\u4ef6\u6f0f\u6d1e",
"number": "CNVD-2017-30818",
"openTime": "2017-10-20",
"patchDescription": "Digium Asterisk Open Source\u548cCertified Asterisk\u90fd\u662f\u7f8e\u56fdDigium\u516c\u53f8\u7684\u5f00\u6e90\u7535\u8bdd\u4ea4\u6362\u673a\uff08PBX\uff09\u7cfb\u7edf\u8f6f\u4ef6\u3002\u8be5\u8f6f\u4ef6\u652f\u6301\u8bed\u97f3\u4fe1\u7bb1\u3001\u591a\u65b9\u8bed\u97f3\u4f1a\u8bae\u3001\u4ea4\u4e92\u5f0f\u8bed\u97f3\u5e94\u7b54(IVR)\u7b49\u3002\r\n\r\nAsterisk Open Source\u548cCertified Asterisk\u4e2d\u5b58\u5728\u5b89\u5168\u6f0f\u6d1e\u3002\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u52ab\u6301\u76ee\u6807\u5a92\u4f53\u7684\u4f1a\u8bdd\u3002\u76ee\u524d\uff0c\u4f9b\u5e94\u5546\u53d1\u5e03\u4e86\u5b89\u5168\u516c\u544a\u53ca\u76f8\u5173\u8865\u4e01\u4fe1\u606f\uff0c\u4fee\u590d\u4e86\u6b64\u6f0f\u6d1e\u3002",
"patchName": "Digium Asterisk Open Source\u548cCertified Asterisk\u4f1a\u8bdd\u52ab\u6301\u6f0f\u6d1e\u7684\u8865\u4e01",
"products": {
"product": [
"Digium Asterisk 13.*\uff0c\u003c13.17.1",
"Digium Asterisk 14.*\uff0c\u003c14.6.1",
"Digium Asterisk 11.*\uff0c\u003c11.25.2",
"Digium Certified Asterisk 11.*\uff0c\u003c11.6-cert17",
"Digium Certified Asterisk 13.*\uff0c\u003c13.13-cert5"
]
},
"referenceLink": "http://downloads.asterisk.org/pub/security/AST-2017-005.html",
"serverity": "\u4e2d",
"submitTime": "2017-09-01",
"title": "Digium Asterisk Open Source\u548cCertified Asterisk\u4f1a\u8bdd\u52ab\u6301\u6f0f\u6d1e"
}
GSD-2017-14099
Vulnerability from gsd - Updated: 2023-12-13 01:21{
"GSD": {
"alias": "CVE-2017-14099",
"description": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.",
"id": "GSD-2017-14099",
"references": [
"https://www.debian.org/security/2017/dsa-3964"
]
},
"gsd": {
"metadata": {
"exploitCode": "unknown",
"remediation": "unknown",
"reportConfidence": "confirmed",
"type": "vulnerability"
},
"osvSchema": {
"aliases": [
"CVE-2017-14099"
],
"details": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.",
"id": "GSD-2017-14099",
"modified": "2023-12-13T01:21:12.562482Z",
"schema_version": "1.4.0"
}
},
"namespaces": {
"cve.org": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2017-14099",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "GLSA-201710-29",
"refsource": "GENTOO",
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"name": "https://issues.asterisk.org/jira/browse/ASTERISK-27013",
"refsource": "CONFIRM",
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"name": "DSA-3964",
"refsource": "DEBIAN",
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"name": "1039251",
"refsource": "SECTRACK",
"url": "http://www.securitytracker.com/id/1039251"
},
{
"name": "http://downloads.asterisk.org/pub/security/AST-2017-005.html",
"refsource": "CONFIRM",
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"name": "https://bugs.debian.org/873907",
"refsource": "CONFIRM",
"url": "https://bugs.debian.org/873907"
},
{
"name": "https://rtpbleed.com",
"refsource": "MISC",
"url": "https://rtpbleed.com"
}
]
}
},
"nvd.nist.gov": {
"configurations": {
"CVE_data_version": "4.0",
"nodes": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.16.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.16.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.14.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.14.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.1.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.3.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.3.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.7.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.7.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.10.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.10.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.12.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.13:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.17.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.16.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.15.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.15.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.0:beta2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.0:beta3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.2.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.2.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.6.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.7.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.8.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.9.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.9.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.12.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.12.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.17.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.15.0:rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.14.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.0:*:*:*:lts:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.0.0:beta1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.1.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.2.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.5.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.5.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.8.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.8.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.11.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.12:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.15.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.15.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.14.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.13.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.1.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.1.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.4.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.4.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.7.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.8.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.11.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.11.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:13.13.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.6.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.4.0:rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.4.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.0:beta1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.1.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.4.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.3.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.3.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.2.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.01:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.2.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.5.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.5.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.3.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.3.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.02:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.6.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.5.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.4.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.4.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.0:beta2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.0.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.1.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:14.1.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.25.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.4.0:rc4:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.6.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.8.0:-:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.8.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.10.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.10.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.12.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.12.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.14.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.14.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.18.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.19.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.22.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.23.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.2.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.2.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.7.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.7.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.9.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.9.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.9.0:rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.11.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.12.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.14.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.14.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.17.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.18.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.21.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.22.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.25.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.2.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.6.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.7.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.8.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.9.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.10.2:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.11.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.13.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.14.0:*:*:*:lts:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.15.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.16.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.17.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.21.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.21.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.24.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.24.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.0:beta1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.0.0:beta2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.0:rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.1.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.6.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.6.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.8.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.8.0:rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.10.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.10.1:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.13.0:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.13.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.15.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.15.0:rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.20.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.21.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.23.0:rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:asterisk:11.23.1:*:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert6:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert10:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert9:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert7:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert8:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert11:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
},
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*",
"cpe_name": [],
"vulnerable": true
}
],
"operator": "OR"
}
]
},
"cve": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2017-14099"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "en",
"value": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://rtpbleed.com",
"refsource": "MISC",
"tags": [
"Third Party Advisory"
],
"url": "https://rtpbleed.com"
},
{
"name": "https://issues.asterisk.org/jira/browse/ASTERISK-27013",
"refsource": "CONFIRM",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"name": "https://bugs.debian.org/873907",
"refsource": "CONFIRM",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugs.debian.org/873907"
},
{
"name": "http://downloads.asterisk.org/pub/security/AST-2017-005.html",
"refsource": "CONFIRM",
"tags": [
"Vendor Advisory"
],
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"name": "1039251",
"refsource": "SECTRACK",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id/1039251"
},
{
"name": "GLSA-201710-29",
"refsource": "GENTOO",
"tags": [],
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"name": "DSA-3964",
"refsource": "DEBIAN",
"tags": [],
"url": "http://www.debian.org/security/2017/dsa-3964"
}
]
}
},
"impact": {
"baseMetricV2": {
"cvssV2": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"severity": "MEDIUM",
"userInteractionRequired": false
},
"baseMetricV3": {
"cvssV3": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
},
"lastModifiedDate": "2017-11-04T01:29Z",
"publishedDate": "2017-09-02T16:29Z"
}
}
}
GHSA-4Q58-999F-6RPW
Vulnerability from github – Published: 2022-05-17 00:27 – Updated: 2022-05-17 00:27In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The "nat" and "rtp_symmetric" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.
{
"affected": [],
"aliases": [
"CVE-2017-14099"
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-09-02T16:29:00Z",
"severity": "HIGH"
},
"details": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.",
"id": "GHSA-4q58-999f-6rpw",
"modified": "2022-05-17T00:27:13Z",
"published": "2022-05-17T00:27:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-14099"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/873907"
},
{
"type": "WEB",
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"type": "WEB",
"url": "https://rtpbleed.com"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"type": "WEB",
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1039251"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
FKIE_CVE-2017-14099
Vulnerability from fkie_nvd - Published: 2017-09-02 16:29 - Updated: 2026-06-17 01:05{
"affected": [
{
"affectedData": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"source": "cve@mitre.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.0:*:*:*:lts:*:*:*",
"matchCriteriaId": "E7D1238A-A8D2-485E-81FD-46038A883EC3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "E93A7967-9A04-424A-BDDB-A2B8289B9AC4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "8F75C9FF-6F95-4F6A-B683-FE2BEDE3AD10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.0:beta3:*:*:*:*:*:*",
"matchCriteriaId": "68226156-42ED-4F0E-93E1-02DD57E582B6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FB2C4E1E-6B90-4DCC-BC09-7D19FBA65C3F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "A4EB385E-28B5-4259-9431-99E1F32D61B7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "58C0FF1B-6188-4181-A139-1806328762BD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.1.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "890EBB8C-989B-4344-AC03-62B399076008",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.1.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "BD4AAECB-A2BC-45BA-BC63-E51C1FE6C334",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "121EACD3-D5E3-4691-8024-95996865BB65",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "136D6508-660E-410D-829A-7DD452BF8819",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.2.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "AEC2B3AA-EB24-4259-BED1-5DBC102FE9C1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "74B23D17-7356-4D37-8C73-E87896D1335B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.3.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "CEA9DA4A-A3E6-4C46-9471-CCBFA71083AF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.3.2:*:*:*:*:*:*:*",
"matchCriteriaId": "81A8A6CB-D236-4AB3-8476-C2D34DB7EF31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "599833A2-CBE9-479B-8A6E-AF79C5EED1DB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.4.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "B55719B3-7325-47E1-8D16-3F34B1F44385",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "B870B3B7-E8DC-45A2-8FA4-657D005D00E3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.5.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "C91E9A3B-54EB-4819-94DD-30F7D0C90047",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.6.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "47189DF9-8E57-4BA6-9F52-B7A8229AE02A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.7.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "84AAFA3C-3CCD-4615-9725-169C303CF18F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.7.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "C92E0801-9E8F-4CF2-A4A0-48BCF550F2D4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5C1C39FA-EF1A-4F2B-87A0-A00BAE73C6A7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.7.2:*:*:*:*:*:*:*",
"matchCriteriaId": "677D1211-0B07-47B9-AB7A-E820E2B29561",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.8.0:*:*:*:*:*:*:*",
"matchCriteriaId": "84202BAF-29E1-472B-B11F-B73F6A8891CF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.8.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "FFC7120D-E6A0-4801-A1CC-3E143896EE72",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.8.1:*:*:*:*:*:*:*",
"matchCriteriaId": "BAF2A83D-D9AE-441D-8D4E-335BF9D28A63",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.8.2:*:*:*:*:*:*:*",
"matchCriteriaId": "7F5C1479-A540-4B7D-B00C-BD35EEC83BB4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "AC12556C-5E82-47D7-87E5-FBDC01A920DD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.9.1:*:*:*:*:*:*:*",
"matchCriteriaId": "461C1D2D-C4C1-4FF8-8231-38A2505F3523",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "66595711-8573-4A9B-A8FE-4943E3097AA8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.10.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "5D1FE3D4-A0B9-475A-9B89-B0222283A6A9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.11.0:*:*:*:*:*:*:*",
"matchCriteriaId": "9670B5AC-CBD1-484C-90F8-69B1A60B6054",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.11.1:*:*:*:*:*:*:*",
"matchCriteriaId": "EE5794B6-246C-415E-8E20-56447F152488",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.11.2:*:*:*:*:*:*:*",
"matchCriteriaId": "E726CA39-A763-4422-B59E-E9E12518EA4D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.12:*:*:*:*:*:*:*",
"matchCriteriaId": "6A96EB57-835A-45B4-82F5-31F925A85629",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.12.0:*:*:*:*:*:*:*",
"matchCriteriaId": "206F1DC9-9E8F-4497-A354-4A14711993DC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.12.1:*:*:*:*:*:*:*",
"matchCriteriaId": "8D428364-E2AD-4BC6-9329-71793BC0EB61",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.12.2:*:*:*:*:*:*:*",
"matchCriteriaId": "08963910-E0BD-4487-B669-60E0BFA79863",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.13:*:*:*:*:*:*:*",
"matchCriteriaId": "86B16D04-3808-4380-8F64-0C36B185C1F2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.13.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F3BD16A9-24BC-4FC1-81BA-A6D1FEF38D35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.13.1:*:*:*:*:*:*:*",
"matchCriteriaId": "68BAAD53-DE75-41CA-BF60-C0363029D3A1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.14.0:*:*:*:*:*:*:*",
"matchCriteriaId": "CDC383B3-27EF-4C37-94BE-F0D41B34CAFC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.14.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "A7824B34-06C3-403B-B6F3-C850D54438EB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.14.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "17E86941-98F6-45A5-8646-6876F74D909F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.14.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C6DB27C0-C74E-4E6A-AA63-09CFE73C2EF6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.15.0:*:*:*:*:*:*:*",
"matchCriteriaId": "6C443A3B-DF96-4A68-B046-DE13689CA974",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.15.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "5F3AC9AE-288C-4F0E-BF15-C3F4AF09D8E0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.15.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "796A6021-9FCA-4354-A47C-7500C363C168",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.15.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "EBB9D073-195F-4C2A-932E-7F027710DB25",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.15.1:*:*:*:*:*:*:*",
"matchCriteriaId": "604E58C8-9B81-4992-8993-4A6CB876EE08",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.16.0:*:*:*:*:*:*:*",
"matchCriteriaId": "077C4CB8-1FDE-45D3-82E6-CE09A22809B1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.16.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "3CDB96CA-5AAE-4B39-8E01-2E72E3B476AE",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.16.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "8EB33EC3-CDE0-40BD-B269-512AE074D278",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.17.0:*:*:*:*:*:*:*",
"matchCriteriaId": "363FA95F-03EF-4D6A-A40D-76D285D16255",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:13.17.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "FA96DC31-4BAC-4C5A-923C-EBBFFC7ABB52",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C949D5F5-6C0B-4B17-85B6-3A77D08CF967",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "5D413741-BDB7-496D-A01B-75E2A98FDB5B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "29130F7F-DE00-43E1-A4A6-8F1F95D5CB19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "25E94EC0-F577-4B2B-8B11-DC76278CDD42",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "101AD474-9B89-483D-84E8-08012677C55C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "D57E41F6-C2CF-4183-A78A-9531A88FB65D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "FB1F9BB8-F951-427E-B770-69C2ACEBDB28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "7C4CE405-E923-4C9C-849A-D1031C4DB493",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C039C0CE-9C9C-4D85-8D7C-574DCF9D920B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.01:*:*:*:*:*:*:*",
"matchCriteriaId": "A1B2F2CC-18C3-46E7-8E7F-970622A710C9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "04ECDFF1-9718-4FAE-B45B-4F8CCA82829E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "D2C4DA60-5701-4BD0-B2F9-D93B9E64111F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "0B12834D-2AF1-4AD1-AB23-859CAA5D3210",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.02:*:*:*:*:*:*:*",
"matchCriteriaId": "89036D04-EA04-4041-9694-6768478D35F3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.2:*:*:*:*:*:*:*",
"matchCriteriaId": "B19070D3-9F03-43C7-9F31-9A54BD5F2441",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "E39BAA74-50A8-4087-8FF8-7C5922121319",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "6D29C253-B403-4B00-A626-3E3A920DC018",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "5E9D8FA2-21EA-4384-8001-118DA7C959F0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.3.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "3368DE88-7009-46A0-93F4-4D52BAD3D173",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.3.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "26586127-B68B-4476-8182-C49B1B1DCDC6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.3.1:*:*:*:*:*:*:*",
"matchCriteriaId": "6D1EFDCC-983E-4227-9FD5-456C16610BC8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "DFA7DBAD-BCA6-47D1-A92E-4EB7941F55F1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.4.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "02C6C827-97A6-4287-8B3E-DE29054242B3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.4.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "9BE4F7C1-BB82-44BA-BBFD-9F660330EC15",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.4.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "E4FCA146-5A72-4746-BE23-63271FBC4D47",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "4A0C90BB-C3FE-4A75-B739-0236C4256F7E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "46BD9466-0BC9-4B4D-928F-240CD46D306C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.5.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "06F456AD-19D3-49EF-82B1-07370F6499AA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.5.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "24A9997E-D0DC-45B0-B4DB-308667FA820E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "26202E79-98E0-4533-B4AE-1ABB2477F5A1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:14.6.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "C3D7384F-DF1B-4ED7-B1D5-885B95774DDB",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F53B8453-F35A-49BE-8129-774BADF71BA7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.0:beta1:*:*:*:*:*:*",
"matchCriteriaId": "CCB0C07E-DA2F-4169-848D-C3315CDC1CB3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.0:beta2:*:*:*:*:*:*",
"matchCriteriaId": "410C43E6-5912-4C22-A592-7CF94402EEB7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "D50A355E-1B55-4DD2-8100-EB81AA6FC40E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "9ADF4230-EFEB-45EC-9C96-0262B4A3E459",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5234531C-F69A-4B94-A480-147734206C5A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "321C1066-6800-4488-A7C4-BE91FF738453",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A9B51588-50A2-40B2-A007-06F57D38C7AA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "CDE2B00C-6AC0-4166-8A25-EFC42CE7F737",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "9FD404B4-2B0A-4D7A-8CF6-E2C6B4BACBB7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "617FC4AF-D152-4EE1-828D-C2A6AD0DFD3B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "3A3FE6DC-17FD-4CEE-BDFB-9D4685640381",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "8CEEB6C2-0A6D-4434-8446-CB8605CD3B14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.2.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "1548C574-CD51-49F6-91B1-B06C504000E4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7BE4127D-8123-4408-86D3-08168A4501B9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "8836F348-66DF-43BC-9962-946018D13127",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.4.0:rc4:*:*:*:*:*:*",
"matchCriteriaId": "1453BB31-D674-4A05-AB2A-2502D127C3E9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.6.0:*:*:*:*:*:*:*",
"matchCriteriaId": "868865A1-E074-4DB0-A119-D24C5C53FEF9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.6.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "1794440C-7068-4673-9142-6221B8A39E5F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.6.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "C5CF286B-3377-4AE9-A7B9-8535641D639A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7B3D89C7-909F-419A-9EE8-A1F0D02934EF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "50EC8D9D-3483-4080-8000-496343BC8BFD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.7.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "6695F632-6AC4-400F-B513-280304ABC1F3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.7.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "A3423C40-240A-4237-8B0F-A4B4ED421C3F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.8.0:-:*:*:*:*:*:*",
"matchCriteriaId": "03298D9F-CFB8-48F9-BD0C-8A0BEB0760C9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.8.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "87FCBE6A-C1CD-48EF-A435-4CEADD46C917",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.8.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "42E0E639-70A2-41EE-9B34-A9223D1958AF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.8.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "32E84D64-0CB8-46BF-BD3F-8CA2E0CE4C57",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.8.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A70420A8-8571-4528-98E1-72BE00270C6E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.9.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A276363F-F897-4E6D-9D55-5F5AA73DEE26",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.9.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "38230656-6242-4D24-AA67-F42A6FA2FC7F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.9.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "20ED9FC3-5E56-4AE7-903F-267CAE7F2CA5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.9.0:rc3:*:*:*:*:*:*",
"matchCriteriaId": "84F88075-9935-45BF-88B7-21ACE8AAB314",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "DB16D9D6-A2F6-4C4B-B364-1B63B1FFB5F0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.10.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "283793E4-0AE8-48D9-ABCF-70E44FE55C4D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.10.1:*:*:*:*:*:*:*",
"matchCriteriaId": "A0F79D5F-EB28-417A-86DF-053D6EDBA161",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.10.1:rc1:*:*:*:*:*:*",
"matchCriteriaId": "4A036F91-70E0-4E97-9896-EEE97BE3C20E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.10.2:*:*:*:*:*:*:*",
"matchCriteriaId": "C92ECBCD-1EE3-498A-B3A4-22BF8EFD2EE7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.11.0:*:*:*:*:*:*:*",
"matchCriteriaId": "C4EABFC3-24FA-4441-9F2B-650D90AE5CC6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.11.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "3DA61A22-3DD0-46A3-8C13-F25F4F03FD35",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.12.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2026FD07-103C-4691-AFA4-88C490382F28",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.12.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "791700CD-E007-489E-9BC6-37025CAA8144",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.12.1:*:*:*:*:*:*:*",
"matchCriteriaId": "65607103-4284-430A-8212-AC1DCFFFA778",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.13.0:*:*:*:*:*:*:*",
"matchCriteriaId": "4061B4C7-8315-450C-866A-C4F3A6BCB1A1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.13.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "C6EA7154-7F08-4E43-9270-E617632230AC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.13.1:*:*:*:*:*:*:*",
"matchCriteriaId": "00099DC9-D437-429B-9D08-F0DFA4942A6C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.14.0:*:*:*:lts:*:*:*",
"matchCriteriaId": "4149F36C-D455-415F-93D7-F92EEE41419D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.14.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "2DC51129-8F38-4505-90FB-4FFDED45BABF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.14.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "4CA571E0-B513-47AA-95BE-EB4DD2AA91E2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.14.1:*:*:*:*:*:*:*",
"matchCriteriaId": "89504BDC-82F7-4813-9C1E-456C9ACC6FB3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.14.2:*:*:*:*:*:*:*",
"matchCriteriaId": "118C550E-79A8-431E-BADB-710EEEEDC6C7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.15.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "96C7950F-41D1-46B5-BA62-E8450CB81244",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.15.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "C9A32ECC-E208-4834-8EF7-FEF7A3495041",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.15.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5DF6BC60-23F5-46A1-83F8-F4BCDEF196EF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.16.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "AA3E0D41-2E6E-4294-8E56-1A738A7F9AA9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.17.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "D16109B8-4CDF-46FC-9AD9-A158E532791B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.17.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9DCAA174-3CA3-49DB-BA19-D2BCF4F8953F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.18.0:*:*:*:*:*:*:*",
"matchCriteriaId": "FD4D1A5A-99A3-4D23-B40C-BBE11EA5B325",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.18.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "0F5EE428-98FF-42BC-9F61-311327B8F610",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.19.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "CBA2FD08-D761-410F-9804-A76F0DD77349",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.20.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "74B34C21-D90B-4E32-BBA6-7773DB663F18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.21.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "90996D49-5731-4F7D-9DBE-D0599A5D85A9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.21.0:rc2:*:*:*:*:*:*",
"matchCriteriaId": "D3C91C8D-707D-443D-985F-FA3EDB181208",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.21.1:*:*:*:*:*:*:*",
"matchCriteriaId": "400EA2E1-B178-467F-BBC2-1B2ECEDE662A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.21.2:*:*:*:*:*:*:*",
"matchCriteriaId": "6E00A6C7-D3CF-40B5-A586-06E09C5AA1A3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.22.0:*:*:*:*:*:*:*",
"matchCriteriaId": "9E25D043-EE0D-49A5-A468-03EDD9CFE0EC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.22.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "CA17630B-444D-4AE4-B582-F8106C4EEFDB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.23.0:*:*:*:*:*:*:*",
"matchCriteriaId": "62A20D6B-62FE-440D-BC58-F764AAA5562B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.23.0:rc1:*:*:*:*:*:*",
"matchCriteriaId": "F2AE880B-2FA2-42BB-BEBF-771E18FDA141",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.23.1:*:*:*:*:*:*:*",
"matchCriteriaId": "AC982D1B-B018-474E-94BE-2157C21276C7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.24.0:*:*:*:*:*:*:*",
"matchCriteriaId": "F26815C8-8E43-4C26-947B-986EFFF0ACE1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.24.1:*:*:*:*:*:*:*",
"matchCriteriaId": "03E8213E-650F-4C95-B9E5-753E7784EF5B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.25.0:*:*:*:*:*:*:*",
"matchCriteriaId": "00B8F794-A7F2-4B8F-B36C-55E61DC6939A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:asterisk:11.25.1:*:*:*:*:*:*:*",
"matchCriteriaId": "5B7FC3A1-AFB0-4280-BFC5-68F61CFD0AF2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:*:*:*:*",
"matchCriteriaId": "322694EF-B086-4BE7-A9F0-41D3A9C245FF",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc1:*:*:*:*:*:*",
"matchCriteriaId": "781AC882-80DD-4176-8E4F-220343B15F68",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert1_rc2:*:*:*:*:*:*",
"matchCriteriaId": "770CCEEA-B121-454B-BD36-3FC1B262998A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert10:*:*:*:*:*:*",
"matchCriteriaId": "5CEBE67E-A3E5-4BC9-8740-4F51123CC9F7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert11:*:*:*:*:*:*",
"matchCriteriaId": "CD094E25-5E10-4564-9A4D-BE5A14C2815F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert12:*:*:*:*:*:*",
"matchCriteriaId": "B6873174-0109-402F-ADCA-B1635F441FD9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert13:*:*:*:*:*:*",
"matchCriteriaId": "B529CD2F-2958-44E6-839A-3E4FE392B1F1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14:*:*:*:*:*:*",
"matchCriteriaId": "B961BF46-DEF7-4804-AF9A-D13F160FA213",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc1:*:*:*:*:*:*",
"matchCriteriaId": "DDC801D4-7A69-4855-8757-24ACE70D784B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert14_rc2:*:*:*:*:*:*",
"matchCriteriaId": "60C2B8F0-7722-48B5-89AA-435F52CBC0A4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert15:*:*:*:*:*:*",
"matchCriteriaId": "B9305CA8-835C-4DFF-9CD8-C1072BACED42",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert16:*:*:*:*:*:*",
"matchCriteriaId": "B3729EA6-3949-4854-80D4-DC5587161FBD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:*:*:*:*",
"matchCriteriaId": "013B1940-C45D-4FE2-8B49-D92B8F1A9048",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:*:*:*:*",
"matchCriteriaId": "A98B11B5-B8E2-4903-B4F7-3AC23751AE8F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:*:*:*:*",
"matchCriteriaId": "C7D60B24-C509-49C3-87A9-49D05CB44183",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:*:*:*:*",
"matchCriteriaId": "3C1F9978-44E7-4D39-BEC6-5C6DB7F893E9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert6:*:*:*:*:*:*",
"matchCriteriaId": "69BA61A8-2A95-4800-BB4E-692BA4321A84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert7:*:*:*:*:*:*",
"matchCriteriaId": "C481D8B0-622D-491D-B292-717B0369B507",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert8:*:*:*:*:*:*",
"matchCriteriaId": "BC8390D4-F339-43FF-9F2B-71331D4ECB81",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:11.6:cert9:*:*:*:*:*:*",
"matchCriteriaId": "4490B76B-FA41-43DB-9A31-6B3F220F1907",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:*",
"matchCriteriaId": "0449B393-FA4E-4664-8E16-BE6B94E4872F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:*",
"matchCriteriaId": "2ED8E415-64FA-4E77-A423-3478E606E58E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:*",
"matchCriteriaId": "E13CA1DD-B384-4408-B4EC-1AA829981016",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:*",
"matchCriteriaId": "EE28BD0A-EA30-4265-A5D6-0390F3558D44",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc4:*:*:*:*:*:*",
"matchCriteriaId": "0F82048D-C65F-4439-BBE4-2D4A9B07EB7E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert2:*:*:*:*:*:*",
"matchCriteriaId": "6447B77F-3770-4703-9188-B7344ED98E94",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert3:*:*:*:*:*:*",
"matchCriteriaId": "5C103924-1D61-4090-8ED5-4731371B2B2C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:digium:certified_asterisk:13.13:cert4:*:*:*:*:*:*",
"matchCriteriaId": "08F87B09-3867-4CAE-BAD7-2206CD6CAF97",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The \"strictrtp\" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The \"nat\" and \"rtp_symmetric\" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well."
},
{
"lang": "es",
"value": "En res/res_rtp_asterisk.c en Asterisk 11.x en versiones anteriores a la 11.25.2, 13.x en versiones anteriores a la 13.17.1, y 14.x en versiones anteriores a la 14.6.1 y Certified Asterisk 11.x en versiones anteriores a la 11.6-cert17 y 13.x en versiones anteriores a la 13.13-cert5, es posible divulgar datos sin autorizaci\u00f3n si un atacante ataca en el momento adecuado. La opci\u00f3n \"strictrtp\" en rtp.conf habilita una caracter\u00edstica de la pila RTP que aprende la direcci\u00f3n de origen de los medios para una sesi\u00f3n y coloca cualquier paquete que no se haya originado a partir de la direcci\u00f3n esperada. Esta opci\u00f3n est\u00e1 activda por defecto en Asterisk 11 y superiores. Las opciones \"nat\" y \"rtp_symmetric\" (para chan_sip y chan_pjsip, respectivamente) permiten el soporte RTP sim\u00e9trico en la pila RTP. Esto emplea la direcci\u00f3n de origen de medios entrantes como direcci\u00f3n de destino de cualquier medio enviado. Esta opci\u00f3n no est\u00e1 activada por defecto, pero suele estar habilitada para gestionar dispositivos tras NAT. Se ha realizado un cambio en el soporte RTP estricto en la pila RTP para tolerar mejor los medios tard\u00edos cuando ocurre una reinvitaci\u00f3n. Cuando se combina con el soporte RTP sim\u00e9trico, esto introdujo una avenida en la que se pod\u00eda secuestrar medios. En vez de solo aprender una nueva direcci\u00f3n cuando se espera, el nuevo c\u00f3digo permit\u00eda una nueva direcci\u00f3n de origen que deb\u00eda ser aprendida en todo momento. Si se recibe un flujo de tr\u00e1fico RTP, el soporte RTP estricto permitir\u00eda que la nueva direcci\u00f3n proporcionase medios, y (con RTP sim\u00e9trico habilitado) el tr\u00e1fico saliente ser\u00eda enviado a esta nueva direcci\u00f3n, permitiendo el secuestro de los medios. Si el atacante contin\u00faa enviando tr\u00e1fico, tambi\u00e9n seguir\u00eda recibi\u00e9ndolo."
}
],
"id": "CVE-2017-14099",
"lastModified": "2026-06-17T01:05:35.187",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "MEDIUM",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2017-09-02T16:29:00.287",
"references": [
{
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
],
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"source": "cve@mitre.org",
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id/1039251"
},
{
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugs.debian.org/873907"
},
{
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
],
"url": "https://rtpbleed.com"
},
{
"source": "cve@mitre.org",
"url": "https://security.gentoo.org/glsa/201710-29"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
],
"url": "http://downloads.asterisk.org/pub/security/AST-2017-005.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.debian.org/security/2017/dsa-3964"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"url": "http://www.securitytracker.com/id/1039251"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugs.debian.org/873907"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://issues.asterisk.org/jira/browse/ASTERISK-27013"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
],
"url": "https://rtpbleed.com"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "https://security.gentoo.org/glsa/201710-29"
}
],
"sourceIdentifier": "cve@mitre.org",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
}
],
"source": "nvd@nist.gov",
"type": "Primary"
}
]
}
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.