VYPR
Medium severity5.8NVD Advisory· Published May 17, 2024· Updated Jun 17, 2026

CVE-2024-35190

CVE-2024-35190

Description

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

Affected products

5
  • Freepbx/Asterisk3 versions
    cpe:2.3:a:sangoma:asterisk:18.23.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sangoma:asterisk:18.23.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:asterisk:20.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sangoma:asterisk:21.3.0:*:*:*:*:*:*:*
  • Asterisk/Asteriskllm-fuzzy2 versions
    before 18.23.1, 20.8.1, and 21.3.1+ 1 more
    • (no CPE)range: before 18.23.1, 20.8.1, and 21.3.1
    • (no CPE)range: = 21.3.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.