6.5

CVE-2025-54995

Exploit
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SangomaAsterisk Version < 18.26.4
SangomaCertified Asterisk Version < 18.9
SangomaCertified Asterisk Version18.9 Updatecert1
SangomaCertified Asterisk Version18.9 Updatecert1-rc1
SangomaCertified Asterisk Version18.9 Updatecert10
SangomaCertified Asterisk Version18.9 Updatecert11
SangomaCertified Asterisk Version18.9 Updatecert12
SangomaCertified Asterisk Version18.9 Updatecert13
SangomaCertified Asterisk Version18.9 Updatecert14
SangomaCertified Asterisk Version18.9 Updatecert15
SangomaCertified Asterisk Version18.9 Updatecert16
SangomaCertified Asterisk Version18.9 Updatecert2
SangomaCertified Asterisk Version18.9 Updatecert3
SangomaCertified Asterisk Version18.9 Updatecert4
SangomaCertified Asterisk Version18.9 Updatecert5
SangomaCertified Asterisk Version18.9 Updatecert6
SangomaCertified Asterisk Version18.9 Updatecert7
SangomaCertified Asterisk Version18.9 Updatecert8
SangomaCertified Asterisk Version18.9 Updatecert8-rc1
SangomaCertified Asterisk Version18.9 Updatecert8-rc2
SangomaCertified Asterisk Version18.9 Updatecert9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.635
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.