📦 Asterisk

by Sangoma

🔍 What is Asterisk?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57520

CRITICAL CVSS 9.8 Feb 5, 2025

CVE-2024-57520 is an insecure permissions vulnerability in Asterisk v22 that allows directory traversal via the action_createconfig function. This could enable arbitrary file creation outside the Aste...

CVE-2025-1131

HIGH CVSS 7.8 Sep 23, 2025

A local privilege escalation vulnerability in Asterisk's safe_asterisk script allows non-root users with write access to /etc/asterisk to execute arbitrary code as root. This occurs because the script...

CVE-2025-57767

HIGH CVSS 7.5 Aug 28, 2025

This vulnerability in Asterisk allows remote attackers to cause a denial of service (crash) by sending specially crafted SIP requests with malformed Authorization headers. The crash occurs due to a NU...

CVE-2025-47779

HIGH CVSS 7.7 May 22, 2025

This vulnerability in Asterisk PBX allows authenticated attackers to spoof user identities when sending SIP MESSAGE requests, enabling them to send spam messages that appear to come from trusted sourc...

CVE-2022-23608

HIGH CVSS 8.1 Feb 22, 2022

This CVE describes a use-after-free vulnerability in PJSIP library versions up to 2.11.1 that occurs in dialog set scenarios. When multiple UAC dialogs share a hash key, premature freeing can cause ha...

CVE-2021-37706

HIGH CVSS 7.3 Dec 22, 2021

CVE-2021-37706 is an integer underflow vulnerability in PJSIP's STUN message processing that allows remote code execution. Attackers on the same network can send specially crafted UDP packets to execu...

CVE-2025-49832

MEDIUM CVSS 6.5 Aug 1, 2025

Asterisk has a vulnerability in its STIR/SHAKEN verification module that allows remote attackers to cause denial of service or potentially execute arbitrary code. This affects Asterisk installations w...

CVE-2024-53566

MEDIUM CVSS 5.5 Dec 2, 2024

A path traversal vulnerability in the action_listcategories() function of Asterisk allows attackers to access files outside the intended directory. This affects Asterisk versions 22.0.0 through 22.0.0...

CVE-2024-35190

MEDIUM CVSS 5.8 May 17, 2024

Asterisk versions 18.23.0 incorrectly identify all unauthorized SIP requests as coming from the local PJSIP endpoint, potentially allowing unauthorized access to telephony services. This affects Aster...

CVE-2026-23738

LOW CVSS 3.5 Feb 6, 2026

This vulnerability allows cross-site scripting (XSS) attacks in Asterisk's web interface. Attackers can inject malicious scripts via cookies or GET parameters, which execute when users visit the /http...

CVE-2026-23739

LOW CVSS 2.0 Feb 6, 2026

This CVE describes an XML External Entity (XXE) vulnerability in Asterisk's XML parsing function. It allows attackers to read sensitive files from the host system when untrusted XML is processed. Affe...