Actually this is not a vulnerability in the product itself, but if you use Asterisk or one of its derivatives such as TrixBox, you should review your SIP and IAX secrets to make sure they are not the same as your extension numbers. As reported by Kerry...
In November 2007 TiGra Networks embarked on a project to evaluate various digital telephony solutions, with a view to implementing our own infrastructure and, in the process, gain the necessary knowledge and experience to offer digital telephony solutions...