#VU22934 Improper access control in Asterisk Open Source and Certified Asterisk - CVE-2019-18790
Published: November 22, 2019
Asterisk Open Source
Certified Asterisk
Digium (Linux Support Services)
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can send a specially crafted SIP request, change a SIP peer’s IP address and hijack the calls.
Note: This vulnerability is only exploitable when the “nat” option is set to the default, or “auto_force_rport”.