CVE-2014-8413: Digium Asterisk
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.conf at startup, which allows remote attackers to bypass intended PJSIP ACL rules.
Affected products
- Digium Asterisk: from 12.0.0, before 12.7.1 (fixed in 12.7.1); from 13.0.0, before 13.0.1 (fixed in 13.0.1)
Published 2014-11-24. Last modified 2026-06-17.