Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-2288

The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and the remote SIP server challenges for authentication of the resulting OPTIONS request," allows remote attackers to cause a denial of service (crash) via a PJSIP endpoint that does not have an associated outgoing request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.299
EPSS Ranking 96.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-2288
  • Digium » Asterisk » Version: 12.0.0
    cpe:2.3:a:digium:asterisk:12.0.0
  • Digium » Asterisk » Version: 12.1.0
    cpe:2.3:a:digium:asterisk:12.1.0


Contact Us

Shodan ® - All rights reserved