Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1897

14
FAUCET Score

CVE-2008-1897 describes a denial-of-service vulnerability in the IAX2 channel driver (chan_iax2) across several Asterisk products, including Open Source, Business Edition, AsteriskNOW, Appliance Developer Kit, and s800i. The flaw allows remote attackers to cause traffic amplification by sending spoofed ACK responses that do not complete a 3-way handshake, specifically when unauthenticated calls are permitted. This vulnerability has a CVSS score of 4.3, indicating a medium severity, with a network attack vector, medium attack complexity, and potential for partial availability impact. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
0.2CPE matchmatch criteria
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.2:*:*:*:*:*:*:*
0.3CPE matchmatch criteria
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.3:*:*:*:*:*:*:*
0.4CPE matchmatch criteria
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.4:*:*:*:*:*:*:*
0.5CPE matchmatch criteria
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.5:*:*:*:*:*:*:*
0.6CPE matchmatch criteria
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.74%
Probability of exploitation in next 30 days
EPSS Percentile
84.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0274 is in the 76th percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2008-1897

asterisk: 3-way handshake in IAX2 incomplete (CVE-2008-1923)

Apr 22, 2008

References

bugs.digium.com / view.php
downloads.digium.com / pub/security/AST-2008-006.html
downloads.asterisk.org / pub/security/AST-2008-006.html
secunia.com / advisories/29927
Vendor Advisory
secunia.com / advisories/30010
Vendor Advisory
secunia.com / advisories/30042
Vendor Advisory
secunia.com / advisories/34982
security.gentoo.org / glsa/glsa-200905-01.xml
exchange.xforce.ibmcloud.com / vulnerabilities/41966
github.com / jcollie/asterisk/commit/60de4fbbdf3ede49f158e23a9e3b679f2e519c1e
github.com / jcollie/asterisk/commit/771b3d8749b34b6eea4e03a2e514380da9582f90
github.com / jcollie/asterisk/commit/a8b180875b037b8da26f6a3bcc8e5e98b8c904d2
github.com / kaoru6/asterisk/commit/1fe14f38dd43dc894d21f85762b51208ba5c8acb
github.com / lyx2014/Asterisk/commit/0670e43c30135044e25cca7f80e1833e2c128653
github.com / mojolingo/asterisk/commit/20ac3662f137dbf7f42d5295590069a7d3b1166b
github.com / pruiz/asterisk/commit/e0ef9bd22810c6969a7f222eec04798f19a7e2d6
github.com / silentindark/asterisk-1/commit/fe8b7f31db687f8b9992864b82c93d22833019c7
github.com / xrg/asterisk-xrg/commit/10da3dab24e8ca08cf2c983f8d0206e383535b5a
github.com / xrg/asterisk-xrg/commit/51714a24347dc57f9a208a4a8af84115ef407b83
redhat.com / archives/fedora-package-announce/2008-April/msg00581.html
redhat.com / archives/fedora-package-announce/2008-April/msg00600.html
altsci.com / concepts/page.php
debian.org / security/2008/dsa-1563
securityfocus.com / archive/1/491220/100/0/threaded
securityfocus.com / bid/28901
securitytracker.com / id
vupen.com / english/advisories/2008/1324