CVE-2021-26906
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.
Se detectó un problema en el archivo res_pjsip_session.c en Digium Asterisk versiones hasta 13.38.1; 14.x, 15.x y 16.xa 16.16.0; 17.xa 17.9.1; y 18.xa 18.2.0, y Certified Asterisk versiones hasta 16.8-cert5. Una vulnerabilidad de negociación SDP en PJSIP permite a un servidor remoto bloquear potencialmente Asterisk mediante el envío de respuestas SIP específicas que causan un fallo en la negociación SDP
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-02-08 CVE Reserved
- 2021-02-18 CVE Published
- 2023-11-04 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/161477/Asterisk-Project-Security-Advisory-AST-2021-005.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://seclists.org/fulldisclosure/2021/Feb/61 | 2021-02-24 | |
https://issues.asterisk.org/jira/browse/ASTERISK-29196 | 2021-02-24 |
URL | Date | SRC |
---|---|---|
https://downloads.asterisk.org/pub/security | 2021-02-24 | |
https://downloads.asterisk.org/pub/security/AST-2021-005.html | 2021-02-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 13.0.0 < 13.38.2 Search vendor "Digium" for product "Asterisk" and version " >= 13.0.0 < 13.38.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 16.0.0 < 16.16.1 Search vendor "Digium" for product "Asterisk" and version " >= 16.0.0 < 16.16.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 17.0.0 < 17.9.2 Search vendor "Digium" for product "Asterisk" and version " >= 17.0.0 < 17.9.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 18.0 < 18.2.1 Search vendor "Digium" for product "Asterisk" and version " >= 18.0 < 18.2.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert1-rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert1-rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert1-rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert1-rc4 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert2 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert3 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert4 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert4-rc1 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert4-rc2 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert4-rc3 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert4-rc4 |
Affected
| ||||||
Digium Search vendor "Digium" | Certified Asterisk Search vendor "Digium" for product "Certified Asterisk" | 16.8 Search vendor "Digium" for product "Certified Asterisk" and version "16.8" | cert5 |
Affected
|