SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-5642

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones…

MEDIUM 5.0EPSS 11.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 11.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.3-digiumphones allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an invalid SDP that defines a media description before the connection description in a SIP request.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
11.65% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
digium/asterisk · digium/asterisk digiumphones · digium/certified asterisk
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.