PT-2021-23137 · Unknown+1 · Freeswitch+1

Sandro Gauci

·

Published

2021-04-13

·

Updated

2023-10-08

·

CVE-2021-41157

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FreeSWITCH versions prior to v1.10.6
Description The issue concerns the lack of authentication for SIP requests of the type SUBSCRIBE in FreeSWITCH. This allows attackers to subscribe to user agent event notifications without authentication, posing privacy concerns and potentially leading to social engineering attacks. For example, attackers may be able to monitor the status of target SIP extensions. SIP SUBSCRIBE messages should be authenticated by default, and FreeSWITCH administrators should not need to explicitly set the auth-subscriptions parameter.
Recommendations For versions prior to v1.10.6, update to version v1.10.6 or later and ensure the configuration is updated accordingly, as software upgrades do not update the configuration by default. As a temporary workaround, consider setting the auth-subscriptions parameter to enable authentication for SIP SUBSCRIBE messages.

Exploit

Fix

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1643
ALT-PU-2021-1703
ALT-PU-2021-3374
ALT-PU-2021-3448
ALT-PU-2023-5726
CVE-2021-41157
GHSA-G7XG-7C54-RMPJ

Affected Products

Alt Linux
Freeswitch