Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-4045

The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a denial of service (assertion failure and crash) via an unsubscribe request when not subscribed to the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.071
EPSS Ranking 91.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-4045
  • Digium » Asterisk » Version: 12.0.0
    cpe:2.3:a:digium:asterisk:12.0.0
  • Digium » Asterisk » Version: 12.1.0
    cpe:2.3:a:digium:asterisk:12.1.0
  • Digium » Asterisk » Version: 12.1.1
    cpe:2.3:a:digium:asterisk:12.1.1
  • Digium » Asterisk » Version: 12.2.0
    cpe:2.3:a:digium:asterisk:12.2.0
  • Digium » Asterisk » Version: 12.3.0
    cpe:2.3:a:digium:asterisk:12.3.0


Contact Us

Shodan ® - All rights reserved