CVE-2014-8412
Summary
| CVE | CVE-2014-8412 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-11-24 15:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8.28 before 1.8.28-cert3 and 11.6 before 11.6-cert8 allows remote attackers to bypass the ACL restrictions via a packet with a source IP that does not share the address family as the first ACL entry. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Digium | Asterisk | All | All | All | All |
| Application | Digium | Certified Asterisk | 1.8.28 | cert1 | All | All |
| Application | Digium | Certified Asterisk | 1.8.28 | cert2 | All | All |
| Application | Digium | Certified Asterisk | 1.8.28.0 | All | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert1 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert2 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert3 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert4 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert5 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert6 | All | All |
| Application | Digium | Certified Asterisk | 11.6 | cert7 | All | All |
| Application | Digium | Certified Asterisk | 11.6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AST-2014-012 | af854a3a-2127-422b-91ae-364da2661108 | downloads.asterisk.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.