Asterisk

Certified Asterisk

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 22.05.2025 16:56:28
  • Zuletzt bearbeitet 23.05.2025 15:55:02

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk c...

  • EPSS 0.09%
  • Veröffentlicht 22.05.2025 16:54:26
  • Zuletzt bearbeitet 23.05.2025 15:55:02

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do ...

  • EPSS 0.44%
  • Veröffentlicht 05.09.2024 18:15:05
  • Zuletzt bearbeitet 26.08.2025 17:47:36

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion ...

Exploit
  • EPSS 34.24%
  • Veröffentlicht 08.08.2024 17:15:19
  • Zuletzt bearbeitet 16.09.2024 20:23:18

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all confi...

  • EPSS 0.05%
  • Veröffentlicht 30.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 06:34:47

res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in a response to a T.38 re-inv...

  • EPSS 0.58%
  • Veröffentlicht 22.02.2022 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:48:55

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario...

  • EPSS 0.27%
  • Veröffentlicht 27.01.2022 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:45:18

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a mal...

  • EPSS 0.1%
  • Veröffentlicht 22.12.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 06:15:45

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribut...

  • EPSS 0.41%
  • Veröffentlicht 06.11.2020 06:15:11
  • Zuletzt bearbeitet 21.11.2024 05:22:30

An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in...

  • EPSS 1.19%
  • Veröffentlicht 02.06.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and...