CVE-2021-32558
Last modified
CVE-2021-32558 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.. EPSS estimates a 9.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Digium | Asterisk | >= 13.0.0, < 13.38.3 |
| Digium | Asterisk | >= 16.0.0, < 16.19.1 |
| Digium | Asterisk | >= 17.0.0, < 17.9.4 |
| Digium | Asterisk | >= 18.0.0, < 18.15.1 |
| Digium | Certified Asterisk | 16.8 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 11.0 |
References
- http://packetstormsecurity.com/files/163639/Asterisk-Project-Security-Advisory-AST-2021-008.htmlPatch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jul/49Mailing List, Patch, Third Party Advisory
- https://downloads.asterisk.org/pub/security/AST-2021-008.htmlPatch, Vendor Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-29392Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00005.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4999Third Party Advisory
- http://packetstormsecurity.com/files/163639/Asterisk-Project-Security-Advisory-AST-2021-008.htmlPatch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Jul/49Mailing List, Patch, Third Party Advisory
- https://downloads.asterisk.org/pub/security/AST-2021-008.htmlPatch, Vendor Advisory
- https://issues.asterisk.org/jira/browse/ASTERISK-29392Exploit, Issue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00005.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2021/dsa-4999Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32558?
How severe is CVE-2021-32558?
How do I fix CVE-2021-32558?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32552It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32553It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32554It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32555It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32556It was discovered that the get_modified_conffiles() function…3.3
- CVE-2021-32557It was discovered that the process_report() function in data…7.1
- CVE-2021-32559An integer overflow exists in pywin32 prior to version b301 …6.5
- CVE-2021-3256KuaiFanCMS V5.x contains an arbitrary file read vulnerabilit…6.5
- CVE-2021-32560The Logging subsystem in OctoPrint before 1.6.0 has incorrec…6.5
- CVE-2021-32561OctoPrint before 1.6.0 allows XSS because API error messages…6.1
- CVE-2021-32563An issue was discovered in Thunar before 4.16.7 and 4.17.x b…9.8
- CVE-2021-32565Invalid values in the Content-Length header sent to Apache T…7.5
Are you affected by CVE-2021-32558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
