Skip to main content

Vendor/product archive

sangoma / asterisk CVEs

Beta · best-effort

28 CVEs tagged to sangoma / asterisk3 Critical, 9 High, 12 Medium, 2 Low, 2 Unrated.

CVE-2026-23741

Published Feb 6, 2026

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_core…

CVSS 0.0 · Unrated
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23740

Published Feb 6, 2026

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb in…

CVSS 0.0 · Unrated
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23739

Published Feb 6, 2026

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23738

Published Feb 6, 2026

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cook…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1131

Published Sep 23, 2025

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-57767

Published Aug 28, 2025

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-57520

Published Feb 5, 2025

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-53566

Published Dec 2, 2024

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35190

Published May 17, 2024

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asteris…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37325

Published Dec 5, 2022

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12228

Published Jun 12, 2018

An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted messag…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2