Session hijacking in Asterisk Open Source and Certified Asterisk - CVE-2017-14099
Published: September 1, 2017
Vulnerability identifier: #VU8063
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14099
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to hijack the target user's media session.
The weakness exists due to a flaw in the strict RTP support feature. A remote attacker can send specially crafted RTP traffic to provide and receive media from the session.
The weakness exists due to a flaw in the strict RTP support feature. A remote attacker can send specially crafted RTP traffic to provide and receive media from the session.
Affected software
Asterisk Open Source
Certified Asterisk
Debian Linux
asterisk (Alpine package)
Certified Asterisk
Debian Linux
asterisk (Alpine package)
How to mitigate CVE-2017-14099
The vulnerability is addressed in the following versions:
Asterisk Open Source - 11.25.2, 13.17.1, 14.6.1.
Certified Asterisk - 11.6-cert17, 13.13-cert5.
Asterisk Open Source - 11.25.2, 13.17.1, 14.6.1.
Certified Asterisk - 11.6-cert17, 13.13-cert5.
asterisk (Alpine package) - update to 14.6.2-r0