Vulnerabilities
Vulnerable Software
Asterisk:  Security Vulnerabilities
The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form.
CVSS Score
7.5
EPSS Score
0.026
Published
2007-03-22
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one valid and one invalid IP address.
CVSS Score
7.8
EPSS Score
0.145
Published
2007-03-21


Contact Us

Shodan ® - All rights reserved