CVE-2012-4737: Digium Asterisk

Medium severity, CVSS 6.0. EPSS: 1.5% chance of exploitation in the next 30 days.

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 does not enforce ACL rules during certain uses of peer credentials, which allows remote authenticated users to bypass intended outbound-call restrictions by leveraging the availability of these credentials.

Affected products

  • Digium Asterisk: version 1.8.0 only; version 1.8.1 only; version 1.8.1.1 only; version 1.8.1.2 only; version 1.8.2 only; version 1.8.2.1 only; …
  • Digium Certified Asterisk: version 1.8.11 only

Published 2012-08-31. Last modified 2026-06-16.