CVE-2008-3263

Asterisk Open Source <1.2.30, 1.4.x <1.4.21.2 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3263. PoCs published by Blake Cornell.

AI-analyzed exploit summary This Perl script exploits CVE-2008-3263, a denial-of-service vulnerability in Asterisk by sending multiple 'POKE' requests via UDP to consume processor resources. It includes modes for scanning, injection, and DoS attacks.

Description

The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (call-number exhaustion and CPU consumption) by quickly sending a large number of IAX2 (IAX) POKE requests.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Blake Cornell · perldoslinux
https://www.exploit-db.com/exploits/32095

This Perl script exploits CVE-2008-3263, a denial-of-service vulnerability in Asterisk by sending multiple 'POKE' requests via UDP to consume processor resources. It includes modes for scanning, injection, and DoS attacks.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Asterisk (versions affected by CVE-2008-3263)
No auth needed
Prerequisites: Network access to the target Asterisk server · UDP port 4569 (or custom port) accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200905-01.xml
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30321
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31194
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43942
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2168/references
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00839.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31178
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494675/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020535
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34982

Scores

EPSS 0.2800
EPSS Percentile 97.9%

Details

CWE
CWE-399
Status published
Products (49)
asterisk/asterisk 0.1.0
asterisk/asterisk 0.1.1
asterisk/asterisk 0.1.2
asterisk/asterisk 0.1.3
asterisk/asterisk 0.1.4
asterisk/asterisk 0.1.5
asterisk/asterisk 0.1.6
asterisk/asterisk 0.1.7
asterisk/asterisk 0.1.8
asterisk/asterisk 0.1.9
... and 39 more
Published Jul 22, 2008
Tracked Since Feb 18, 2026