CVE-2021-31878: Medium severity asterisk vulnerability
Published Jul 27, 2021
·Updated
An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.
Affected Software
6 affected components
Asterisk=16.17.0
Asterisk=16.18.0
Asterisk=16.19.0
Asterisk=18.3.0
Asterisk=18.4.0
Asterisk=18.5.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 27, 2021
CVE Published
via MITRE·05:17 AM
Data Sourced
via MITRE·05:17 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-31878.
2
What is the severity level of CVE-2021-31878?
The severity level of CVE-2021-31878 is medium with a score of 6.5.
3
How does the vulnerability in CVE-2021-31878 occur?
The vulnerability in CVE-2021-31878 occurs when a re-INVITE without SDP is received after Asterisk has sent a BYE request.
4
Which versions of Asterisk are affected by CVE-2021-31878?
Asterisk versions 16.17.0, 16.18.0, 16.19.0, 18.3.0, 18.4.0, and 18.5.0 are affected by CVE-2021-31878.
5
How can I fix the vulnerability in CVE-2021-31878?
To fix the vulnerability in CVE-2021-31878, it is recommended to update to Asterisk versions 16.19.1 or 18.5.1.