Denial of Service Vulnerability in Asterisk Firmware Download Implementation
CVE-2008-3264
Currently unrated
Key Information:
- Vendor
Asterisk
- Vendor
- CVE Published:
- 24 July 2008
What is CVE-2008-3264?
The FWDOWNL firmware-download process in Asterisk Open Source versions prior to 1.2.30 and 1.4.21.2, along with certain Business Edition products, is susceptible to a remote denial of service attack. Attackers can exploit this vulnerability by sending specially crafted IAX2 FWDOWNL requests, leading to traffic amplification and subsequent denial of service conditions for affected systems. Proper security measures and patches should be applied to mitigate this risk.