Vulnerability Details CVE-2007-4103
The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when configured to allow unauthenticated calls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of calls that do not complete a 3-way handshake, which causes an ast_channel to be allocated but not released.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.032
EPSS Ranking 86.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.8
Products affected by CVE-2007-4103
-
cpe:2.3:a:digium:asterisk:1.2.20
-
cpe:2.3:a:digium:asterisk:1.2.21
-
cpe:2.3:a:digium:asterisk:1.2.21.1
-
cpe:2.3:a:digium:asterisk:1.2.22
-
cpe:2.3:a:digium:asterisk:1.4.0
-
cpe:2.3:a:digium:asterisk:1.4.1
-
cpe:2.3:a:digium:asterisk:1.4.2
-
cpe:2.3:a:digium:asterisk:1.4.3
-
cpe:2.3:a:digium:asterisk:1.4.4
-
cpe:2.3:a:digium:asterisk:1.4.5
-
cpe:2.3:a:digium:asterisk:1.4.6
-
cpe:2.3:a:digium:asterisk:1.4.7
-
cpe:2.3:a:digium:asterisk:1.4.7.1
-
cpe:2.3:a:digium:asterisk:1.4.8
-
cpe:2.3:a:digium:asterisk_appliance_developer_kit:-