Vulnerability Details CVE-2008-5558
Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname matching.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.8%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2008-5558
-
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.4
-
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.5
-
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.0
-
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.1
-
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.3
-
cpe:2.3:a:asterisk:open_source:1.2.26
-
cpe:2.3:a:asterisk:open_source:1.2.26.1
-
cpe:2.3:a:asterisk:open_source:1.2.26.2
-
cpe:2.3:a:asterisk:open_source:1.2.27
-
cpe:2.3:a:asterisk:open_source:1.2.28
-
cpe:2.3:a:asterisk:open_source:1.2.29
-
cpe:2.3:a:asterisk:open_source:1.2.30
-
cpe:2.3:a:asterisk:open_source:1.2.30.2
-
cpe:2.3:a:asterisk:open_source:1.2.30.3