CVE-2018-7286

MEDIUM

Asterisk 13.x-13.19.1, 14.x<14.7.5, 15.x-15.2.1, Certified Asterisk <13.18 - DoS via SIP INVITE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-7286. PoCs published by EnableSecurity.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in Asterisk's PJSIP channel driver by sending repeated INVITE messages over TLS and abruptly closing the connection, causing a segmentation fault.

Description

An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.

Exploits (1)

exploitdb WORKING POC VERIFIED
by EnableSecurity · pythondoslinux
https://www.exploit-db.com/exploits/44181

This exploit demonstrates a denial-of-service vulnerability in Asterisk's PJSIP channel driver by sending repeated INVITE messages over TLS and abruptly closing the connection, causing a segmentation fault.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Asterisk (15.2.0 and earlier, 13.19.0 and earlier, 14.7.5 and earlier) with chan_pjsip
Auth required
Prerequisites: Valid SIP credentials · TLS/TCP connectivity to the target Asterisk server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4320
Vendor Advisory x_refsource_confirm
https://issues.asterisk.org/jira/browse/ASTERISK-27618
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44181/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040417
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103129

Scores

CVSS v3 6.5
EPSS 0.3950
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (4)
debian/debian_linux 9.0
digium/asterisk 13.19.1
digium/asterisk 14.0.0 - 14.7.5
digium/certified_asterisk < 13.18
Published Feb 22, 2018
Tracked Since Feb 18, 2026