SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-26498

An issue was discovered in Asterisk through 19.x.

HIGH 7.5EPSS 16.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 16.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
16.65% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
digium/asterisk · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.