CVE-2023-49786
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2023-49786 is a Denial of Service (DoS) vulnerability affecting Asterisk, an open-source private branch exchange and telephony toolkit. Versions prior to 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, are susceptible to this issue. The vulnerability stems from a race condition in the DTLS protocol's hello handshake phase during media setup for DTLS-SRTP. An attacker can continuously exploit this race condition, preventing new DTLS-SRTP encrypted calls from being established, potentially causing a massive DoS on vulnerable Asterisk servers. A fix for this vulnerability is available in commit d7d7764cb07c8a1872804321302ef93bf62cba05, which is included in versions 18.20.1, 20.5.1, 21.0.1, and 18.9-cert6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.