Vulnerability record · CVE-2015-3008 · published 10 April 2015
CVE-2015-3008: Asterisk SIP TLS certificate CN null byte allows server spoofing
Digium · Asterisk
Asterisk fails to properly handle a null byte in the Common Name (CN) field of an X.509 certificate when registering a SIP TLS device. A certificate issued by a legitimate CA with a crafted CN can therefore be accepted for a domain it should not match. This enables man-in-the-middle spoofing of arbitrary SSL servers in affected Asterisk deployments.
Description
Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not properly handle a null byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw requires a man-in-the-middle position and a CA-issued crafted certificate, and CVSS v2 rates it medium with only partial integrity impact.
What it is
Asterisk fails to properly handle a null byte in the Common Name (CN) field of an X.509 certificate when registering a SIP TLS device. A certificate issued by a legitimate CA with a crafted CN can therefore be accepted for a domain it should not match. This enables man-in-the-middle spoofing of arbitrary SSL servers in affected Asterisk deployments.
Impact
An attacker positioned on the network path can impersonate a legitimate SIP TLS server and intercept or alter traffic. The CVSS v2 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.
Attack surface
Reached over the network during SIP TLS device registration; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required but exploitation depends on conditions such as a crafted CA-issued certificate and a man-in-the-middle position. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is 0.46156 (98.756th percentile), and references include a vendor advisory but no public exploit tag.
What to do
- Upgrade Asterisk Open Source to 1.8.32.3, 11.17.1, 12.8.2, or 13.3.2, or Certified Asterisk to 1.8.28-cert5, 11.6-cert11, or 13.1-cert2 as applicable.
- Apply the vendor advisory AST-2015-003 and any distribution backports for Asterisk packages.
- Restrict SIP TLS exposure to trusted networks and enforce certificate validation where possible.
- Monitor for unexpected certificate changes or SIP TLS registration anomalies.
Detection
- Inspect X.509 certificates presented to Asterisk for null bytes or malformed CN fields.
- Monitor SIP TLS registration logs for unexpected server identities or certificate mismatches.
- Use network monitoring to detect man-in-the-middle positioning on SIP TLS paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3008 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3008), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.