Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-41145— FreeSWITCH susceptible to Denial of Service via SIP flooding

CVSS 8.6 · High EPSS 0.95% · P77
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-41145

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FreeSWITCH susceptible to Denial of Service via SIP flooding
Source: NVD (National Vulnerability Database)
Vulnerability Description
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it was observed that after a number of seconds the process was killed by the operating system due to memory exhaustion. By abusing this vulnerability, an attacker is able to crash any FreeSWITCH instance by flooding it with SIP messages, leading to Denial of Service. The attack does not require authentication and can be carried out over UDP, TCP or TLS. This issue was patched in version 1.10.7.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: NVD (National Vulnerability Database)
Vulnerability Title
FreeSWITCH 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FreeSWITCH是美国Anthony Minessale个人开发者的研发的一套免费、开源的通信软件。该软件可用于创建音、视频以及短消息类产品和应用。 FreeSWITCH 存在资源管理错误漏洞,该漏洞源于版本1.10.7之前的FreeSWITCH很容易通过SIP洪水拒绝服务。攻击者可利用该漏洞用SIP消息淹没任何freeeswitch实例,从而导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
signalwirefreeswitch < 1.10.7 -

II. Public POCs for CVE-2021-41145

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-41145

登录查看更多情报信息。

Same Patch Batch · signalwire · 2021-10-25 · 3 CVEs total

CVE-2021-376247.5 HIGHFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofin
CVE-2021-411057.5 HIGHFreeSWITCH susceptible to Denial of Service via invalid SRTP packets

IV. Related Vulnerabilities

V. Comments for CVE-2021-41145

No comments yet


Leave a comment