CVE-2021-26712

Name
CVE-2021-26712
Description
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://downloads.asterisk.org/pub/security/
Mailing List http://seclists.org/fulldisclosure/2021/Feb/59
Vendor Advisory https://downloads.asterisk.org/pub/security/AST-2021-003.html
Issue Tracking https://issues.asterisk.org/jira/browse/ASTERISK-29260
Third Party Advisory http://packetstormsecurity.com/files/161473/Asterisk-Project-Security-Advisory-AST-2021-003.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 13.0.0 <= 13.38.2
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 16.0.0 < 16.16.1
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 17.0.0 < 17.9.2
cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* asterisk >= 18.0 < 18.2.1
cpe:2.3:a:digium:certified_asterisk:16.8:-:*:*:*:*:*:* certified_asterisk == None == 16.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
asterisk 3.10-main 16.3.0-r3 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk 3.11-main 16.6.2-r1 Timo Teras <timo.teras@iki.fi> possibly vulnerable