{"id":"CVE-2023-49786","summary":"Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation","details":"Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1; as well as certified-asterisk prior to 18.9-cert6; Asterisk is susceptible to a DoS due to a race condition in the hello handshake phase of the DTLS protocol when handling DTLS-SRTP for media setup. This attack can be done continuously, thus denying new DTLS-SRTP encrypted calls during the attack. Abuse of this vulnerability may lead to a massive Denial of Service on vulnerable Asterisk servers for calls that rely on DTLS-SRTP. Commit d7d7764cb07c8a1872804321302ef93bf62cba05 contains a fix, which is part of versions 18.20.1, 20.5.1, 21.0.1, amd 18.9-cert6.","aliases":["GHSA-hxj9-xwr8-w8pq"],"modified":"2026-08-12T14:51:40.434155Z","published":"2023-12-14T19:47:46.306Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-703"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49786.json"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/176251/Asterisk-20.1.0-Denial-Of-Service.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Dec/24"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/12/15/7"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49786.json"},{"type":"ADVISORY","url":"https://github.com/EnableSecurity/advisories/tree/master/ES2023-01-asterisk-dtls-hello-race"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-hxj9-xwr8-w8pq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49786"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/commit/d7d7764cb07c8a1872804321302ef93bf62cba05"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"14d0e59f3d8f7521621561168ef4a297702d978f"},{"introduced":"de4f63b4824c91a0cd9f3d95f3b7923bec71960c"},{"fixed":"f7a8ac086de697db30e376d589a6f4e17cfabef5"},{"introduced":"12da95e53ff42287ad69d6d5922e06c3d62010ac"},{"fixed":"d7d7764cb07c8a1872804321302ef93bf62cba05"}],"database_specific":{"cpe":["cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:21.0.0:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:16.8.0:-:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"18.20.1"},{"introduced":"19.0.0"},{"fixed":"20.5.1"},{"introduced":"21.0.0"},{"last_affected":"21.0.0"},{"introduced":"13.13.0"},{"last_affected":"13.13.0"},{"introduced":"13.13.0-rc1"},{"last_affected":"13.13.0-rc1"},{"introduced":"13.13.0-rc2"},{"last_affected":"13.13.0-rc2"},{"introduced":"16.8.0-NA"},{"last_affected":"16.8.0-NA"},{"introduced":"18.9-cert1"},{"last_affected":"18.9-cert1"},{"introduced":"18.9-cert2"},{"last_affected":"18.9-cert2"},{"introduced":"18.9-cert3"},{"last_affected":"18.9-cert3"},{"introduced":"18.9-cert4"},{"last_affected":"18.9-cert4"},{"introduced":"18.9-cert5"},{"last_affected":"18.9-cert5"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["13.13.0","13.13.0-rc1","13.13.0-rc2","16.8.0-NA","18.9-cert1","18.9-cert2","18.9-cert3","18.9-cert4","18.9-cert5","21.0.0","= 21.0.0","20.5.0","18.20.0","20.5.0-rc1","18.20.0-rc1","20.4.0","18.19.0","18.19.0-rc2","20.4.0-rc2","20.4.0-rc1","18.19.0-rc1","20.3.1","18.18.1","20.3.0","18.18.0","20.3.0-rc1","18.18.0-rc1","20.2.1","18.17.1","20.2.0","18.17.0","20.2.0-rc1","18.17.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49786.json","vanir_signatures_modified":"2026-08-12T14:51:40Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["194195294654478782208597305809601381073","299699359499787369045199906154423754698","303643776200746914043500213424152276932"],"threshold":0.9},"id":"CVE-2023-49786-082e6411","signature_type":"Line","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/d7d7764cb07c8a1872804321302ef93bf62cba05","target":{"file":"res/res_rtp_asterisk.c"}},{"deprecated":false,"digest":{"length":3200,"function_hash":"117532334825260400145575307068614735389"},"id":"CVE-2023-49786-7a4ad233","signature_type":"Function","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/d7d7764cb07c8a1872804321302ef93bf62cba05","target":{"file":"res/res_rtp_asterisk.c","function":"__rtp_recvfrom"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}