Vulnerability record · CVE-2017-14098 · published 2 September 2017
CVE-2017-14098: Asterisk res_pjsip tel URI parsing crash in SIP headers
Digium · Asterisk
Asterisk's pjsip channel driver (res_pjsip) fails to properly validate a crafted tel URI placed in a From, To, or Contact header, causing the process to crash. The flaw affects Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, and because the malformed header arrives over the network without authentication, it can take down a SIP service.
Description
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote input can crash a core telephony service, and the high EPSS score indicates elevated exploitation likelihood despite no KEV listing.
What it is
Asterisk's pjsip channel driver (res_pjsip) fails to properly validate a crafted tel URI placed in a From, To, or Contact header, causing the process to crash. The flaw affects Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, and because the malformed header arrives over the network without authentication, it can take down a SIP service.
Impact
An attacker can cause a denial of service by crashing the Asterisk process, interrupting voice services for all users on the affected system. No data confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
The flaw is reached remotely over the network via SIP messages containing a crafted tel URI in a From, To, or Contact header. The CVSS vector indicates no privileges and no user interaction are required, so an unauthenticated sender can trigger it.
Exploitation
CVE-2017-14098 is not listed in CISA KEV, but EPSS is high at roughly 0.50 probability (98.8th percentile), suggesting meaningful likelihood of exploitation activity. References are vendor advisories, patch notes, and issue trackers; none are tagged as exploit code.
What to do
- Upgrade Asterisk to 13.17.1 or 14.6.1 or later, per vendor advisory AST-2017-007.
- If immediate upgrade is not possible, restrict SIP exposure to trusted networks and block untrusted sources at the firewall.
- Apply vendor or distribution patches (for example the Debian fix referenced in the advisory) where packaged versions are used.
- Monitor and rate-limit SIP traffic to reduce the chance of repeated crash attempts against the service.
Detection
- Watch for Asterisk process restarts or core dumps correlated with inbound SIP messages.
- Inspect SIP From, To, and Contact headers for malformed or unusual tel URIs.
- Alert on repeated SIP requests from a single source that precede service interruptions.
- Review Asterisk logs and security advisories for crash signatures tied to res_pjsip header parsing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://downloads.asterisk.org/pub/security/AST-2017-007.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/100583 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039253 | Third Party AdvisoryVDB Entry |
| https://bugs.debian.org/873909 | Issue TrackingPatchThird Party Advisory |
| https://issues.asterisk.org/jira/browse/ASTERISK-27152 | Issue TrackingVendor Advisory |
| http://downloads.asterisk.org/pub/security/AST-2017-007.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/100583 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039253 | Third Party AdvisoryVDB Entry |
| https://bugs.debian.org/873909 | Issue TrackingPatchThird Party Advisory |
| https://issues.asterisk.org/jira/browse/ASTERISK-27152 | Issue TrackingVendor Advisory |
Track CVE-2017-14098 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14098), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.