Sangoma

Asterisk

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 06.02.2026 16:47:19
  • Zuletzt bearbeitet 18.02.2026 18:42:31

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 of the ast_c...

  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 16:43:41
  • Zuletzt bearbeitet 10.02.2026 18:25:39

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that is world-writable (for example ...

  • EPSS 0.07%
  • Veröffentlicht 06.02.2026 16:42:25
  • Zuletzt bearbeitet 18.02.2026 18:42:37

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe parsing options that enab...

  • EPSS 0.05%
  • Veröffentlicht 06.02.2026 16:41:43
  • Zuletzt bearbeitet 18.02.2026 18:42:48

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are directly interpolated into...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.09.2025 05:15:35
  • Zuletzt bearbeitet 03.11.2025 18:15:48

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc...

  • EPSS 0.1%
  • Veröffentlicht 28.08.2025 15:33:00
  • Zuletzt bearbeitet 20.10.2025 17:51:12

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Aut...

Exploit
  • EPSS 0.91%
  • Veröffentlicht 28.08.2025 15:16:02
  • Zuletzt bearbeitet 03.11.2025 18:17:00

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustio...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 22.05.2025 16:56:28
  • Zuletzt bearbeitet 03.11.2025 20:19:05

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk c...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 22.05.2025 16:54:26
  • Zuletzt bearbeitet 03.11.2025 20:19:05

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do ...

  • EPSS 3.52%
  • Veröffentlicht 05.02.2025 22:15:32
  • Zuletzt bearbeitet 06.11.2025 13:15:35

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the As...