📦 Certified Asterisk

by Sangoma

🔍 What is Certified Asterisk?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1131

HIGH CVSS 7.8 Sep 23, 2025

A local privilege escalation vulnerability in Asterisk's safe_asterisk script allows non-root users with write access to /etc/asterisk to execute arbitrary code as root. This occurs because the script...

CVE-2025-47779

HIGH CVSS 7.7 May 22, 2025

This vulnerability in Asterisk PBX allows authenticated attackers to spoof user identities when sending SIP MESSAGE requests, enabling them to send spam messages that appear to come from trusted sourc...

CVE-2023-37457

HIGH CVSS 7.5 Dec 14, 2023

Asterisk contains a buffer overflow vulnerability in the PJSIP_HEADER dialplan function's 'update' functionality. This can cause memory corruption or crashes, potentially leading to denial of service ...

CVE-2023-49786

HIGH CVSS 7.5 Dec 14, 2023

A race condition in Asterisk's DTLS-SRTP handshake allows attackers to cause denial of service by preventing new encrypted calls from being established. This affects Asterisk servers using DTLS-SRTP f...

CVE-2025-49832

MEDIUM CVSS 6.5 Aug 1, 2025

Asterisk has a vulnerability in its STIR/SHAKEN verification module that allows remote attackers to cause denial of service or potentially execute arbitrary code. This affects Asterisk installations w...

CVE-2026-23738

LOW CVSS 3.5 Feb 6, 2026

This vulnerability allows cross-site scripting (XSS) attacks in Asterisk's web interface. Attackers can inject malicious scripts via cookies or GET parameters, which execute when users visit the /http...

CVE-2026-23739

LOW CVSS 2.0 Feb 6, 2026

This CVE describes an XML External Entity (XXE) vulnerability in Asterisk's XML parsing function. It allows attackers to read sensitive files from the host system when untrusted XML is processed. Affe...