CVE-2018-12227 is a low-severity information disclosure vulnerability affecting Asterisk Open Source and Certified Asterisk versions. It allows an attacker to determine if a SIP request targets a defined endpoint by observing the difference in response codes (403 vs. 401) when ACL rules block a request or an endpoint is unidentified. This vulnerability has a CVSS score of 5.3 (Medium) with a network attack vector and low attack complexity, but it only discloses endpoint existence and does not bypass ACL rules for unauthorized access. There is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.0, < 13.21.1CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
> 14.0.0, < 14.7.7CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
>= 15.0.0, < 15.4.1CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
13.18CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.18:cert1:*:*:*:*:*:* | ||
13.18CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:13.18:cert2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.