PT-2021-21740 · Unknown+1 · Freeswitch+1
Andywolk
·
Published
2021-10-25
·
Updated
2023-10-08
·
CVE-2021-37624
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeSWITCH versions prior to 1.10.7
Description
The issue concerns the lack of authentication for SIP MESSAGE requests in FreeSWITCH, leading to potential spam and message spoofing. By default, SIP requests of the type MESSAGE are not authenticated, allowing attackers to send messages to any SIP user agent registered with the server without requiring authentication. This can enable social engineering, phishing, and similar attacks. The maintainers recommend that this SIP message type be authenticated by default.
Recommendations
For versions prior to 1.10.7, update to version 1.10.7 to resolve the issue. As a temporary workaround, consider setting the
auth-messages parameter to true to enable authentication for SIP MESSAGE requests. Restrict access to the SIP MESSAGE endpoint to minimize the risk of exploitation. Avoid relying on the default setting and explicitly configure authentication for SIP MESSAGE requests.Exploit
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Freeswitch