VYPR
Medium severity5.3OSV Advisory· Published Jun 12, 2018· Updated Jun 17, 2026

CVE-2018-12227

CVE-2018-12227

Description

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not identified, then a 401 unauthorized response is sent. This vulnerability just discloses which requests hit a defined endpoint. The ACL rules cannot be bypassed to gain access to the disclosed endpoints.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Digium/AsteriskOSV2 versions
    13.18.0, 13.18.0-rc1, 13.18.0-rc2, …+ 1 more
    • (no CPE)range: 13.18.0, 13.18.0-rc1, 13.18.0-rc2, …
    • cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*range: >=13.0.0,<13.21.1
  • cpe:2.3:a:digium:certified_asterisk:13.18:cert1:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:digium:certified_asterisk:13.18:cert1:*:*:*:*:*:*
    • cpe:2.3:a:digium:certified_asterisk:13.18:cert2:*:*:*:*:*:*
    • cpe:2.3:a:digium:certified_asterisk:13.18:cert3:*:*:*:*:*:*
    • cpe:2.3:a:digium:certified_asterisk:13.21:cert1:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • Range: 13.18-cert <13.18-cert4, 13.21-cert <13.21-cert2
  • Range: 13.x <13.21.1, 14.x <14.7.7, 15.x <15.4.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.