https://seclists.org/oss-sec/2023/q4/283: [ES2023-01] Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
Published Dec 15, 2023
·Updated
Affected Software
1 affected component
Asterisk Asterisk>20.1.0
The severity of ES2023-01 is categorized as high due to the potential for Denial of Service attacks.
To fix ES2023-01, upgrade Asterisk to one of the fixed versions: 18.20.1, 20.5.1, 21.0.1, or 18.9-cert6.
ES2023-01 allows an attacker to perform a Denial of Service attack via DTLS Hello packets during call initiation.
Asterisk versions prior to 18.20.1, 20.5.1, 21.0.1, and 18.9-cert6 are affected by ES2023-01.
The vulnerability ES2023-01 was published on December 15, 2023.