Vulnerability Name: CVE-2021-26717 (CCN-197035) Assigned: 2020-12-08 Published: 2020-12-08 Updated: 2021-02-24 Summary: An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash. CVSS v3 Severity: 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2021-26717 Source: MISC Type: Third Party Advisoryhttp://packetstormsecurity.com/files/161471/Asterisk-Project-Security-Advisory-AST-2021-002.html Source: FULLDISC Type: Mailing List, Patch, Third Party Advisory20210218 AST-2021-002: Remote crash possible when negotiating T.38 Source: MISC Type: Vendor Advisoryhttps://downloads.asterisk.org/pub/security/ Source: CCN Type: Asterisk Project Security Advisory - AST-2021-002Remote crash possible when negotiating T.38 Source: CONFIRM Type: Vendor Advisoryhttps://downloads.asterisk.org/pub/security/AST-2021-002.html Source: XF Type: UNKNOWNasterisk-cve202126717-dos(197035) Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisoryhttps://issues.asterisk.org/jira/browse/ASTERISK-29203 Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2021-26717 Vulnerable Configuration: Configuration 1 :cpe:/a:digium:asterisk:*:*:*:*:*:*:*:* (Version >= 16.0.0 and < 16.16.1)OR cpe:/a:digium:asterisk:*:*:*:*:*:*:*:* (Version >= 17.0.0 and < 17.9.2) OR cpe:/a:digium:asterisk:*:*:*:*:*:*:*:* (Version >= 18.0 and < 18.2.1) OR cpe:/a:digium:certified_asterisk:16.8:-:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert1-rc1:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert1-rc2:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert1-rc3:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert1-rc4:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert2:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert3:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert4:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert4-rc1:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert4-rc2:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert4-rc3:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert4-rc4:*:*:*:*:*:* OR cpe:/a:digium:certified_asterisk:16.8:cert5:*:*:*:*:*:* Denotes that component is vulnerable BACK
digium asterisk *
digium asterisk *
digium asterisk *
digium certified asterisk 16.8 -
digium certified asterisk 16.8 cert1-rc1
digium certified asterisk 16.8 cert1-rc2
digium certified asterisk 16.8 cert1-rc3
digium certified asterisk 16.8 cert1-rc4
digium certified asterisk 16.8 cert2
digium certified asterisk 16.8 cert3
digium certified asterisk 16.8 cert4
digium certified asterisk 16.8 cert4-rc1
digium certified asterisk 16.8 cert4-rc2
digium certified asterisk 16.8 cert4-rc3
digium certified asterisk 16.8 cert4-rc4
digium certified asterisk 16.8 cert5