Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Digium Asterisk安全绕过和拒绝服务漏洞
Vulnerability Description
Digium Asterisk是美国Digium公司的一套开源的电话交换机(PBX)系统软件。该软件支持语音信箱、多方语音会议、交互式语音应答(IVR)等。 Asterisk Open Source 1.4.40.1之前版本,1.6.1.25,1.6.2.17.3和1.8.3.3版本以及Asterisk Business Edition C.3.6.4之前版本中存在安全绕过和拒绝服务漏洞。 (1)应用程序没有正确限制同步TCP连接的数量。远程攻击者可利用此漏洞消耗所有可利用文件的描述符,并从处理新的调用中
CVSS Information
N/A
Vulnerability Type
N/A