Asterisk

Asterisk

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.52%
  • Veröffentlicht 05.02.2025 22:15:32
  • Zuletzt bearbeitet 06.11.2025 13:15:35

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the As...

  • EPSS 0.96%
  • Veröffentlicht 05.09.2024 18:15:05
  • Zuletzt bearbeitet 03.11.2025 22:18:06

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion ...

Exploit
  • EPSS 31.95%
  • Veröffentlicht 08.08.2024 17:15:19
  • Zuletzt bearbeitet 03.11.2025 22:18:05

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all confi...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 17.05.2024 17:15:07
  • Zuletzt bearbeitet 26.08.2025 16:19:01

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

  • EPSS 3.53%
  • Veröffentlicht 04.02.2010 20:15:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP Fa...

  • EPSS 0.75%
  • Veröffentlicht 08.09.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800...

Exploit
  • EPSS 36.1%
  • Veröffentlicht 22.07.2008 23:41:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x befor...

  • EPSS 2.65%
  • Veröffentlicht 24.03.2008 17:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 ge...

  • EPSS 1.06%
  • Veröffentlicht 20.03.2008 00:44:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 re...

  • EPSS 2.42%
  • Veröffentlicht 28.08.2007 01:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient l...