Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-3264


The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (traffic amplification) via an IAX2 FWDOWNL request.


Published

2008-07-24T15:41:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware asterisk s800i_appliance 1.0 No
Hardware asterisk s800i_appliance 1.0.1 No
Hardware asterisk s800i_appliance 1.0.2 No
Hardware asterisk s800i_appliance 1.0.3 No
Application asterisk asterisk_appliance_developer_kit 0.2 Yes
Application asterisk asterisk_appliance_developer_kit 0.3 Yes
Application asterisk asterisk_appliance_developer_kit 0.4 Yes
Application asterisk asterisk_appliance_developer_kit 0.5 Yes
Application asterisk asterisk_appliance_developer_kit 0.6 Yes
Application asterisk asterisk_appliance_developer_kit 0.6.0 Yes
Application asterisk asterisk_appliance_developer_kit 0.7 Yes
Application asterisk asterisk_appliance_developer_kit 0.8 Yes
Application asterisk asterisk_business_edition a Yes
Application asterisk asterisk_business_edition b Yes
Application asterisk asterisk_business_edition b.1.3.2 Yes
Application asterisk asterisk_business_edition b.1.3.3 Yes
Application asterisk asterisk_business_edition b.2.2.0 Yes
Application asterisk asterisk_business_edition b.2.2.1 Yes
Application asterisk asterisk_business_edition b.2.3.1 Yes
Application asterisk asterisk_business_edition b.2.3.2 Yes
Application asterisk asterisk_business_edition b.2.3.3 Yes
Application asterisk asterisk_business_edition b.2.3.4 Yes
Application asterisk asterisk_business_edition b.2.3.6 Yes
Application asterisk asterisk_business_edition b.2.5.0 Yes
Application asterisk asterisk_business_edition b.2.5.3 Yes
Application asterisk asterisk_business_edition b2.5.1 Yes
Application asterisk asterisk_business_edition b2.5.2 Yes
Application asterisk asterisk_business_edition c Yes
Application asterisk asterisk_business_edition c.1.0-beta7 Yes
Application asterisk asterisk_business_edition c.1.0-beta8 Yes
Application asterisk asterisk_business_edition c.1.6 Yes
Application asterisk asterisk_business_edition c.1.6.1 Yes
Application asterisk asterisk_business_edition c.1.6.2 Yes
Application asterisk asterisk_business_edition c1.8.0 Yes
Application asterisk asterisk_business_edition c1.8.1 Yes
Application asterisk asterisknow beta_5 Yes
Application asterisk asterisknow beta_6 Yes
Application asterisk asterisknow beta_7 Yes
Application asterisk asterisknow pre-release Yes
Application asterisk open_source 1.0 Yes
Application asterisk open_source 1.0.0 Yes
Application asterisk open_source 1.0.1 Yes
Application asterisk open_source 1.0.2 Yes
Application asterisk open_source 1.0.3 Yes
Application asterisk open_source 1.0.3.4 Yes
Application asterisk open_source 1.0.4 Yes
Application asterisk open_source 1.0.5 Yes
Application asterisk open_source 1.0.6 Yes
Application asterisk open_source 1.0.7 Yes
Application asterisk open_source 1.0.8 Yes
Application asterisk open_source 1.0.9 Yes
Application asterisk open_source 1.0.11 Yes
Application asterisk open_source 1.0.11.1 Yes
Application asterisk open_source 1.0.12 Yes
Application asterisk open_source 1.2.0 Yes
Application asterisk open_source 1.2.0beta1 Yes
Application asterisk open_source 1.2.0beta2 Yes
Application asterisk open_source 1.2.1 Yes
Application asterisk open_source 1.2.2 Yes
Application asterisk open_source 1.2.3 Yes
Application asterisk open_source 1.2.4 Yes
Application asterisk open_source 1.2.5 Yes
Application asterisk open_source 1.2.6 Yes
Application asterisk open_source 1.2.7 Yes
Application asterisk open_source 1.2.7.1 Yes
Application asterisk open_source 1.2.8 Yes
Application asterisk open_source 1.2.9 Yes
Application asterisk open_source 1.2.9.1 Yes
Application asterisk open_source 1.2.10 Yes
Application asterisk open_source 1.2.11 Yes
Application asterisk open_source 1.2.12 Yes
Application asterisk open_source 1.2.12.1 Yes
Application asterisk open_source 1.2.13 Yes
Application asterisk open_source 1.2.14 Yes
Application asterisk open_source 1.2.15 Yes
Application asterisk open_source 1.2.16 Yes
Application asterisk open_source 1.2.17 Yes
Application asterisk open_source 1.2.18 Yes
Application asterisk open_source 1.2.19 Yes
Application asterisk open_source 1.2.20 Yes
Application asterisk open_source 1.2.21 Yes
Application asterisk open_source 1.2.21.1 Yes
Application asterisk open_source 1.2.22 Yes
Application asterisk open_source 1.2.23 Yes
Application asterisk open_source 1.2.24 Yes
Application asterisk open_source 1.2.25 Yes
Application asterisk open_source 1.2.26 Yes
Application asterisk open_source 1.2.26.1 Yes
Application asterisk open_source 1.2.26.2 Yes
Application asterisk open_source 1.2.27 Yes
Application asterisk open_source 1.2.28 Yes
Application asterisk open_source 1.2.29 Yes
Application asterisk open_source 1.4.0 Yes
Application asterisk open_source 1.4.1 Yes
Application asterisk open_source 1.4.2 Yes
Application asterisk open_source 1.4.3 Yes
Application asterisk open_source 1.4.4 Yes
Application asterisk open_source 1.4.5 Yes
Application asterisk open_source 1.4.6 Yes
Application asterisk open_source 1.4.7 Yes
Application asterisk open_source 1.4.7.1 Yes
Application asterisk open_source 1.4.8 Yes
Application asterisk open_source 1.4.9 Yes
Application asterisk open_source 1.4.10 Yes
Application asterisk open_source 1.4.10.1 Yes
Application asterisk open_source 1.4.11 Yes
Application asterisk open_source 1.4.12 Yes
Application asterisk open_source 1.4.12.1 Yes
Application asterisk open_source 1.4.13 Yes
Application asterisk open_source 1.4.14 Yes
Application asterisk open_source 1.4.15 Yes
Application asterisk open_source 1.4.16 Yes
Application asterisk open_source 1.4.16.1 Yes
Application asterisk open_source 1.4.16.2 Yes
Application asterisk open_source 1.4.17 Yes
Application asterisk open_source 1.4.18 Yes
Application asterisk open_source 1.4.18.1 Yes
Application asterisk open_source 1.4.19 Yes
Application asterisk open_source 1.4.19.1 Yes
Application asterisk open_source 1.4.19_rc3 Yes
Application asterisk open_source 1.4_revision_95946 Yes
Application asterisk open_source 1.4beta Yes

References