Skip to main content

Vendor/product archive

digium / asterisk CVEs

Beta · best-effort

114 CVEs tagged to digium / asterisk5 Critical, 37 High, 67 Medium, 5 Low, 0 Unrated.

CVE-2023-49294

Published Dec 14, 2023

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-ce…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26499

Published Apr 15, 2022

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26498

Published Apr 15, 2022

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31878

Published Jul 30, 2021

An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must be received after Asterisk has sent a BYE request.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26712

Published Feb 18, 2021

Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prema…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26906

Published Feb 18, 2021

An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certifie…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26717

Published Feb 18, 2021

An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35776

Published Feb 18, 2021

A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35652

Published Jan 29, 2021

An issue was discovered in res_pjsip_diversion.c in Sangoma Asterisk before 13.38.0, 14.x through 16.x before 16.15.0, 17.x before 17.9.0, and 18.x before 18.1.0. A crash can occu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15297

Published Sep 9, 2019

res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15639

Published Sep 9, 2019

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7550

Published May 23, 2019

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7251

Published Mar 28, 2019

An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19278

Published Nov 14, 2018

Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 114 CVEsPage 1 of 5