Session hijacking in Asterisk Open Source and Certified Asterisk - CVE-2017-14099

 

Session hijacking in Asterisk Open Source and Certified Asterisk - CVE-2017-14099

Published: September 1, 2017


Vulnerability identifier: #VU8063
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14099
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to hijack the target user's media session.

The weakness exists due to a flaw in the strict RTP support feature. A remote attacker can send specially crafted RTP traffic to provide and receive media from the session.

Affected software

Asterisk Open Source
Certified Asterisk
Debian Linux
asterisk (Alpine package)

How to mitigate CVE-2017-14099

The vulnerability is addressed in the following versions:
Asterisk Open Source - 11.25.2, 13.17.1, 14.6.1.
Certified Asterisk - 11.6-cert17, 13.13-cert5.

asterisk (Alpine package) - update to 14.6.2-r0

External References

Related Security Bulletins