Sangoma

Asterisk

18 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Published 23.09.2025 05:15:35
  • Last modified 08.10.2025 20:35:00

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc...

  • EPSS 0.02%
  • Published 02.12.2024 18:15:11
  • Last modified 06.02.2025 02:15:10

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.

  • EPSS 0.44%
  • Published 05.09.2024 18:15:05
  • Last modified 26.08.2025 17:47:36

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion ...

Exploit
  • EPSS 0.24%
  • Published 17.05.2024 17:15:07
  • Last modified 26.08.2025 16:19:01

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

  • EPSS 0.2%
  • Published 05.12.2022 21:15:10
  • Last modified 24.04.2025 15:15:50

An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk c...

  • EPSS 1.03%
  • Published 05.12.2022 21:15:10
  • Last modified 24.04.2025 15:15:50

A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport ...

  • EPSS 0.27%
  • Published 05.12.2022 21:15:10
  • Last modified 24.04.2025 15:15:47

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

  • EPSS 0.58%
  • Published 22.02.2022 20:15:07
  • Last modified 21.11.2024 06:48:55

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario...

  • EPSS 0.27%
  • Published 27.01.2022 00:15:07
  • Last modified 21.11.2024 06:45:18

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a mal...

  • EPSS 0.1%
  • Published 22.12.2021 18:15:07
  • Last modified 21.11.2024 06:15:45

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribut...