AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-9372

HIGH · CVSS 7.5 EPSS 3.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-06-02 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2017-9372
Severity
HIGH
CVSS
7.5
EPSS
3.99%

Original NVD Description

PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP packet with a crafted CSeq header in conjunction with a Via header that lacks a branch parameter.

Related CVEs

Other vulnerabilities affecting the same vendor(s)