Improper access control in Asterisk Open Source and Certified Asterisk - CVE-2019-18790
Published: November 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can send a specially crafted SIP request, change a SIP peer’s IP address and hijack the calls.
Note: This vulnerability is only exploitable when the “nat” option is set to the default, or “auto_force_rport”.
Affected software
Certified Asterisk
asterisk (Alpine package)
How to mitigate CVE-2019-18790
Certified Asterisk - update to 13.21-cert5
asterisk (Alpine package) - addressed in versions 16.3.0-r3, 16.6.2-r0