Information disclosure in Asterisk Open Source - #VU13262
Published: June 12, 2018 / Updated: June 12, 2018
Asterisk Open Source
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error when the system is configured with endpoint-specific access control list (ACL) rules. A remote attacker can send a SIP request to cause the system to return a 403 Forbidden response and disclose the existence of the PJSIP endpoint.