Vulnerability Details CVE-2014-6609
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.9%
CVSS Severity
CVSS v2 Score 4.0
Products affected by CVE-2014-6609
-
cpe:2.3:a:digium:asterisk:12.0.0
-
cpe:2.3:a:digium:asterisk:12.1.0
-
cpe:2.3:a:digium:asterisk:12.2.0
-
cpe:2.3:a:digium:asterisk:12.3.0
-
cpe:2.3:a:digium:asterisk:12.4.0
-
cpe:2.3:a:digium:asterisk:12.5.0