Hi all, It has already been quite a while.
I noticed that after installing Update 8A, a new option was added to the trunks and it is disabled by default:
"Allow Carrier Side Transfers (SIP REFER)".
I assume this may be related to the security vulnerability. Without claiming that this is the exact issue being addressed, it does seem like a plausible connection.
Sending the REFER:
The attacker sends a SIP REFER request with a Refer-To header pointing to an international premium-rate number,
for example: Refer-To: sip:
[email protected]
But I am not claiming anything, as I did not verify the SIP packet contents prior to the update, and I cannot confirm whether this feature was enabled in the unpatched version 20.0.8. I don't know if that this feature
(SIP REFER) was enabled by default in version 20.0.8 .
In any case, the update only takes a few seconds.
Restarting the server takes longer than applying the micro-update itself.
Good day !
