AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-6610

MEDIUM · CVSS 4 EPSS 1.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-11-26 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.

CVE
CVE-2014-6610
Severity
MEDIUM
CVSS
4
EPSS
1.52%

Original NVD Description

Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.