← Back

CVE-2014-8414

nvd nist
Published: Nov 24, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of service (channel hang and memory consumption) by causing transitions to be delayed, which triggers a state change from hung up to waiting for media.

Affected (9)

2 products
Asterisk
Certified Asterisk
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 11.14.0
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.6.0
Version 11.6 cert1
Version 11.6 cert2
Version 11.6 cert3
Version 11.6 cert4
Version 11.6 cert5
Version 11.6 cert6
Version 11.6 cert7

Related CWEs

References (4)

Timeline

No history available yet.