CVE-2017-17090 describes a denial-of-service vulnerability affecting Asterisk Open Source versions 13.18.2 and older, 14.7.2 and older, 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. An unauthenticated attacker can exploit this by flooding the chan_skinny (SCCP protocol) channel driver with specific requests, leading to excessive virtual memory consumption and ultimately causing the Asterisk process to cease functioning. This vulnerability has a CVSSv3 score of 7.5 (High), indicating a network-based attack with low complexity and high availability impact. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-43992) for remote memory corruption exists, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 13.13CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:*:*:*:*:*:*:*:* | ||
13.13CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.13:cert1:*:*:*:*:*:* | ||
13.13CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc1:*:*:*:*:*:* | ||
13.13CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc2:*:*:*:*:*:* | ||
13.13CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.13:cert1_rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.