
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-26906 is a vulnerability discovered in Digium Asterisk's PJSIP channel driver, affecting versions through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, as well as Certified Asterisk through 16.8-cert5. The vulnerability was reported on December 4, 2020, by Mauri de Souza Meneguzzo from 3CPlus and was publicly disclosed on February 8, 2021 (Asterisk Advisory).
The vulnerability exists in the res_pjsip_session.c component, specifically in the SDP negotiation process. The code responsible for negotiating SDP in SIP responses incorrectly assumes that SDP negotiation will always be successful. The issue occurs when a SIP response containing an SDP that cannot be negotiated is received, causing a subsequent SDP negotiation on the same call to trigger a crash. This vulnerability has been assigned a CVSS v3.1 Base Score of 5.9 (Medium) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
When exploited, this vulnerability can lead to a denial of service condition through a crash of the Asterisk system. The crash can be triggered under specific conditions involving SDP negotiation failures during call setup, particularly affecting outgoing calls from Asterisk to remote SIP servers (Asterisk Advisory).
The vulnerability can be triggered remotely without authentication, though it requires specific timing conditions to be met. The crash occurs when a race condition is triggered where a second SDP negotiation happens before the call termination due to an initial SDP negotiation failure. This can happen in several scenarios, including when the 'accept_multiple_sdp_answers' option is set to 'yes' or when using the default 'follow_early_media_fork' setting (Asterisk Advisory).
The issue has been fixed in PJSIP by modifying the behavior of the pjmedia_sdp_neg_modify_local_offer2 function to properly check if SDP was successfully negotiated rather than assuming success. Fixed versions include Asterisk Open Source 13.38.2, 16.16.1, 17.9.2, 18.2.1, and Certified Asterisk 16.8-cert6. Users are advised to upgrade to these patched versions (Asterisk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."