SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-37706

A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine.

CRITICAL 9.8EPSS 4.58%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.58% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-191
Affected
teluu/pjsip · asterisk/certified asterisk · sangoma/asterisk · debian/debian linux
Source
security-advisories@github.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.