6.5

CVE-2025-54995

Exploit

Asterisk remotely exploitable leak of RTP UDP ports and internal resources

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sangoma ≫ Asterisk Version < 18.26.4
Sangoma ≫ Certified Asterisk Version < 18.9
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert10
Sangoma ≫ Certified Asterisk Version 18.9 Update cert11
Sangoma ≫ Certified Asterisk Version 18.9 Update cert12
Sangoma ≫ Certified Asterisk Version 18.9 Update cert13
Sangoma ≫ Certified Asterisk Version 18.9 Update cert14
Sangoma ≫ Certified Asterisk Version 18.9 Update cert15
Sangoma ≫ Certified Asterisk Version 18.9 Update cert16
Sangoma ≫ Certified Asterisk Version 18.9 Update cert2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert3
Sangoma ≫ Certified Asterisk Version 18.9 Update cert4
Sangoma ≫ Certified Asterisk Version 18.9 Update cert5
Sangoma ≫ Certified Asterisk Version 18.9 Update cert6
Sangoma ≫ Certified Asterisk Version 18.9 Update cert7
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.389
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-1286 Improper Validation of Syntactic Correctness of Input

The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.

CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9
Patch
https://github.com/asterisk/asterisk/commit/eafcd7a451dcd007dddf324ac37dd55a4808338d
Patch
https://github.com/asterisk/asterisk/pull/1405
Issue Tracking
https://github.com/asterisk/asterisk/pull/1406
Issue Tracking
https://github.com/asterisk/asterisk/security/advisories/GHSA-557q-795j-wfx2
Vendor Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html