Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41105

Опубликовано: 25 окт. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. When handling SRTP calls, FreeSWITCH prior to version 1.10.7 is susceptible to a DoS where calls can be terminated by remote attackers. This attack can be done continuously, thus denying encrypted calls during the attack. When a media port that is handling SRTP traffic is flooded with a specially crafted SRTP packet, the call is terminated leading to denial of service. This issue was reproduced when using the SDES key exchange mechanism in a SIP environment as well as when using the DTLS key exchange mechanism in a WebRTC environment. The call disconnection occurs due to line 6331 in the source file switch_rtp.c, which disconnects the call when the total number of SRTP errors reach a hard-coded threshold (100). By abusing this vulnerability, an attacker is able to disconnect any ongoing calls that are us

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freeswitch:freeswitch:*:*:*:*:*:*:*:*
Версия до 1.10.7 (исключая)

EPSS

Процентиль: 89%
0.0442
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
debian
больше 4 лет назад

FreeSWITCH is a Software Defined Telecom Stack enabling the digital tr ...

EPSS

Процентиль: 89%
0.0442
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
NVD-CWE-Other