CVE-2026-23741
- EPSS 0.05%
- Veröffentlicht 06.02.2026 16:47:19
- Zuletzt bearbeitet 18.02.2026 18:42:31
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 of the ast_c...
CVE-2026-23740
- EPSS 0.02%
- Veröffentlicht 06.02.2026 16:43:41
- Zuletzt bearbeitet 10.02.2026 18:25:39
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that is world-writable (for example ...
CVE-2026-23739
- EPSS 0.07%
- Veröffentlicht 06.02.2026 16:42:25
- Zuletzt bearbeitet 18.02.2026 18:42:37
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe parsing options that enab...
CVE-2026-23738
- EPSS 0.05%
- Veröffentlicht 06.02.2026 16:41:43
- Zuletzt bearbeitet 18.02.2026 18:42:48
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, user supplied/control values for Cookies and any GET variable query Parameter are directly interpolated into...
CVE-2025-1131
- EPSS 0.05%
- Veröffentlicht 23.09.2025 05:15:35
- Zuletzt bearbeitet 03.11.2025 18:15:48
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc...
CVE-2025-57767
- EPSS 0.1%
- Veröffentlicht 28.08.2025 15:33:00
- Zuletzt bearbeitet 20.10.2025 17:51:12
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Aut...
CVE-2025-54995
- EPSS 0.91%
- Veröffentlicht 28.08.2025 15:16:02
- Zuletzt bearbeitet 03.11.2025 18:17:00
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustio...
CVE-2025-49832
- EPSS 0.18%
- Veröffentlicht 01.08.2025 17:57:29
- Zuletzt bearbeitet 04.08.2025 15:06:15
Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-cert6, 21.00.0, 22.00.0 through 22.5.0, there is a remote DoS and possible RCE condition in `asterisk...
CVE-2025-47780
- EPSS 0.58%
- Veröffentlicht 22.05.2025 16:56:28
- Zuletzt bearbeitet 03.11.2025 20:19:05
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk c...
CVE-2025-47779
- EPSS 0.28%
- Veröffentlicht 22.05.2025 16:54:26
- Zuletzt bearbeitet 03.11.2025 20:19:05
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do ...