PT-2021-21740 · Unknown+1 · Freeswitch+1

Andywolk

·

Published

2021-10-25

·

Updated

2023-10-08

·

CVE-2021-37624

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeSWITCH versions prior to 1.10.7
Description The issue concerns the lack of authentication for SIP MESSAGE requests in FreeSWITCH, leading to potential spam and message spoofing. By default, SIP requests of the type MESSAGE are not authenticated, allowing attackers to send messages to any SIP user agent registered with the server without requiring authentication. This can enable social engineering, phishing, and similar attacks. The maintainers recommend that this SIP message type be authenticated by default.
Recommendations For versions prior to 1.10.7, update to version 1.10.7 to resolve the issue. As a temporary workaround, consider setting the auth-messages parameter to true to enable authentication for SIP MESSAGE requests. Restrict access to the SIP MESSAGE endpoint to minimize the risk of exploitation. Avoid relying on the default setting and explicitly configure authentication for SIP MESSAGE requests.

Exploit

Fix

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3374
ALT-PU-2021-3448
ALT-PU-2023-5726
CVE-2021-37624
GHSA-MJCM-Q9H8-9XV3

Affected Products

Alt Linux
Freeswitch