CVE-2017-17090

HIGH

Certified Asterisk < 13.13 - Denial of Service via SCCP Request Flood

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-17090. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit targets a memory exhaustion vulnerability in Asterisk by sending a crafted SCCP packet, leading to a denial of service (DoS) condition. The PoC continuously sends the malicious packet to the target, causing the system to run out of memory.

Description

An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Sacco · pythondosmultiple
https://www.exploit-db.com/exploits/43992

This exploit targets a memory exhaustion vulnerability in Asterisk by sending a crafted SCCP packet, leading to a denial of service (DoS) condition. The PoC continuously sends the malicious packet to the target, causing the system to run out of memory.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Asterisk 13.17.2~dfsg-2
No auth needed
Prerequisites: Network access to the target Asterisk server · Target must be running a vulnerable version of Asterisk
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039948
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43992/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102023
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.asterisk.org/jira/browse/ASTERISK-27452
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2017/12/msg00028.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2017/dsa-4076

Scores

CVSS v3 7.5
EPSS 0.8151
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-459
Status published
Products (3)
digium/asterisk < 13.8.2
digium/certified_asterisk 13.13 cert1 (11 CPE variants)
digium/certified_asterisk < 13.13
Published Dec 02, 2017
Tracked Since Feb 18, 2026