// For flags

CVE-2012-3553

Asterisk Project Security Advisory - AST-2012-009

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and closing a connection in off-hook mode, a related issue to CVE-2012-2948.

chan_skinny.c en el controlador de canal de Skinny (alias SCCP) en Asterisk Open Source v10.x antes v10.5.1 permite a usuarios remotos autenticados provocar una denegación de servicio (eliminar la referencia del puntero NULL y caída demonio) mediante el envío de un mensaje Station Key Pad Button y el cierre de una conexión en modo descolgado, un tema relacionado con CVE-2012-2948.

AST-2012-008 previously dealt with a denial of service attack exploitable in the Skinny channel driver that occurred when certain messages are sent after a previously registered station sends an Off Hook message. Unresolved in that patch is an issue in the Asterisk 10 releases, wherein, if a Station Key Pad Button Message is processed after an Off Hook message, the channel driver will inappropriately dereference a Null pointer. Similar to AST-2012-008, a remote attacker with a valid SCCP ID can can use this vulnerability by closing a connection to the Asterisk server when a station is in the "Off Hook" call state and crash the server.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-06-14 CVE Reserved
  • 2012-06-14 CVE Published
  • 2024-09-17 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
beta1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
beta2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
rc1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
rc2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.0
Search vendor "Digium" for product "Asterisk" and version "10.0.0"
rc3
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.0.1
Search vendor "Digium" for product "Asterisk" and version "10.0.1"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.0
Search vendor "Digium" for product "Asterisk" and version "10.1.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.0
Search vendor "Digium" for product "Asterisk" and version "10.1.0"
rc1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.0
Search vendor "Digium" for product "Asterisk" and version "10.1.0"
rc2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.1
Search vendor "Digium" for product "Asterisk" and version "10.1.1"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.2
Search vendor "Digium" for product "Asterisk" and version "10.1.2"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.1.3
Search vendor "Digium" for product "Asterisk" and version "10.1.3"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.0
Search vendor "Digium" for product "Asterisk" and version "10.2.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.0
Search vendor "Digium" for product "Asterisk" and version "10.2.0"
rc1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.0
Search vendor "Digium" for product "Asterisk" and version "10.2.0"
rc2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.0
Search vendor "Digium" for product "Asterisk" and version "10.2.0"
rc3
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.0
Search vendor "Digium" for product "Asterisk" and version "10.2.0"
rc4
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.2.1
Search vendor "Digium" for product "Asterisk" and version "10.2.1"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.3.0
Search vendor "Digium" for product "Asterisk" and version "10.3.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.3.0
Search vendor "Digium" for product "Asterisk" and version "10.3.0"
rc2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.3.0
Search vendor "Digium" for product "Asterisk" and version "10.3.0"
rc3
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.3.1
Search vendor "Digium" for product "Asterisk" and version "10.3.1"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.0
Search vendor "Digium" for product "Asterisk" and version "10.4.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.0
Search vendor "Digium" for product "Asterisk" and version "10.4.0"
rc1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.0
Search vendor "Digium" for product "Asterisk" and version "10.4.0"
rc2
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.0
Search vendor "Digium" for product "Asterisk" and version "10.4.0"
rc3
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.1
Search vendor "Digium" for product "Asterisk" and version "10.4.1"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.4.2
Search vendor "Digium" for product "Asterisk" and version "10.4.2"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.5.0
Search vendor "Digium" for product "Asterisk" and version "10.5.0"
-
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.5.0
Search vendor "Digium" for product "Asterisk" and version "10.5.0"
rc1
Affected
Digium
Search vendor "Digium"
Asterisk
Search vendor "Digium" for product "Asterisk"
10.5.0
Search vendor "Digium" for product "Asterisk" and version "10.5.0"
rc2
Affected