← Vulnerability feed

Vulnerability record · CVE-2015-3008 · published 10 April 2015

CVE-2015-3008: Asterisk SIP TLS certificate CN null byte allows server spoofing

Digium · Asterisk

Asterisk fails to properly handle a null byte in the Common Name (CN) field of an X.509 certificate when registering a SIP TLS device. A certificate issued by a legitimate CA with a crafted CN can therefore be accepted for a domain it should not match. This enables man-in-the-middle spoofing of arbitrary SSL servers in affected Asterisk deployments.

4.3 CVSS 2.0 Medium EPSS 46% · top 1.2% CWE-310 · CWE-310
4.3CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not properly handle a null byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityThe flaw requires a man-in-the-middle position and a CA-issued crafted certificate, and CVSS v2 rates it medium with only partial integrity impact.

What it is

Asterisk fails to properly handle a null byte in the Common Name (CN) field of an X.509 certificate when registering a SIP TLS device. A certificate issued by a legitimate CA with a crafted CN can therefore be accepted for a domain it should not match. This enables man-in-the-middle spoofing of arbitrary SSL servers in affected Asterisk deployments.

Impact

An attacker positioned on the network path can impersonate a legitimate SIP TLS server and intercept or alter traffic. The CVSS v2 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.

Attack surface

Reached over the network during SIP TLS device registration; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required but exploitation depends on conditions such as a crafted CA-issued certificate and a man-in-the-middle position. No user interaction is indicated.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded. EPSS is 0.46156 (98.756th percentile), and references include a vendor advisory but no public exploit tag.

What to do

  • Upgrade Asterisk Open Source to 1.8.32.3, 11.17.1, 12.8.2, or 13.3.2, or Certified Asterisk to 1.8.28-cert5, 11.6-cert11, or 13.1-cert2 as applicable.
  • Apply the vendor advisory AST-2015-003 and any distribution backports for Asterisk packages.
  • Restrict SIP TLS exposure to trusted networks and enforce certificate validation where possible.
  • Monitor for unexpected certificate changes or SIP TLS registration anomalies.

Detection

  • Inspect X.509 certificates presented to Asterisk for null bytes or malformed CN fields.
  • Monitor SIP TLS registration logs for unexpected server identities or certificate mismatches.
  • Use network monitoring to detect man-in-the-middle positioning on SIP TLS paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3008 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26651Digium asterisk sql injection vulnerabilityAn issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi…EPSS 7.0%9.8CVE-2017-14100Digium asterisk os command injection vulnerabilityIn Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cer…EPSS 15%9.1CVE-2022-26499Digium asterisk server-side request forgery (ssrf) vulnerabilityAn SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces s…EPSS 7.8%9.0CVE-2014-8418Digium certified asterisk permissions and access controls vulnerabilityThe DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified …EPSS 3.6%9.0CVE-2011-1599Digium asterisk improper input validation vulnerabilitymanager.c in the Manager Interface in Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x befor…EPSS 3.1%8.8CVE-2019-18610Digium asterisk missing authorization vulnerabilityAn issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenti…EPSS 30%8.8CVE-2017-16671Digium asterisk memory buffer overflow vulnerabilityA Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13…EPSS 3.3%8.8CVE-2017-7617Digium asterisk memory buffer overflow vulnerabilityRemote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 be…EPSS 6.2%

Source: NIST National Vulnerability Database (record CVE-2015-3008), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.