← Vulnerability feed

Vulnerability record · CVE-2007-2297 · published 26 April 2007

CVE-2007-2297: Asterisk vulnerability

Asterisk · Asterisk

The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).

7.8 CVSS 2.0 High EPSS 2.4% · top 16.7%
7.8CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packets that do not contain a valid response code, which allows remote attackers to cause a denial of service (crash).

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2297 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2488Asterisk vulnerabilityThe IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss …EPSS 4.3%9.3CVE-2008-1390Asterisk vulnerabilityThe AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, Asteri…EPSS 3.8%9.3CVE-2007-3762Asterisk vulnerabilityStack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1,…EPSS 5.5%8.8CVE-2024-42365Asterisk vulnerabilityAsterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-…EPSS 4.7%8.8CVE-2008-1332Asterisk permissions and access controls vulnerabilityUnspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…EPSS 2.3%7.8CVE-2009-2346Asterisk memory buffer overflow vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.…EPSS 2.6%7.8CVE-2008-3263Asterisk vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …EPSS 28%7.8CVE-2007-2294Asterisk vulnerabilityThe Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 auth…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2007-2297), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.