VYPR

Asterisk

by Asterisk

Source repositories

CVEs (79)

  • CVE-2017-14100CriSep 2, 2017
    risk 0.65cvss 9.8epss 0.15

    In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is…

  • CVE-2024-57520CriFeb 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka…

  • CVE-2022-26651CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly…

  • CVE-2022-26499CriApr 15, 2022
    risk 0.60cvss 9.1epss 0.08

    An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.

  • CVE-2018-7284HigFeb 22, 2018
    risk 0.56cvss 7.5epss 0.58

    A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept…

  • CVE-2017-17850HigDec 27, 2017
    risk 0.55cvss 7.5epss 0.75

    An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and…

  • CVE-2018-17281HigSep 24, 2018
    risk 0.53cvss 7.5epss 0.53

    There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to…

  • CVE-2017-14098HigSep 2, 2017
    risk 0.53cvss 7.5epss 0.50

    In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.

  • CVE-2025-1131HigSep 23, 2025
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root,…

  • CVE-2025-47780HigMay 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI)…

  • CVE-2025-47779HigMay 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An…

  • CVE-2022-26498HigApr 15, 2022
    risk 0.50cvss 7.5epss 0.16

    An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and…

  • CVE-2021-26717HigFeb 18, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in…

  • CVE-2019-18976HigNov 22, 2019
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different…

  • CVE-2009-3723HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    asterisk allows calls on prohibited networks

  • CVE-2016-7550HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.02

    asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

  • CVE-2018-7285HigFeb 22, 2018
    risk 0.49cvss 7.5epss 0.05

    A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a codec using a different payload number, these desired ones…

  • CVE-2017-14603HigOct 10, 2017
    risk 0.49cvss 7.5epss 0.03

    In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and…

  • CVE-2017-14099HigSep 2, 2017
    risk 0.49cvss 7.5epss 0.04

    In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an…

  • CVE-2007-4103HigJul 31, 2007
    risk 0.49cvss 7.5epss 0.06

    The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Developer Kit before 0.6.0, when configured to allow unauthenticated calls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood…

Page 1 of 4