Digium Certified Asterisk vulnerabilities
51 known vulnerabilities affecting digium/certified_asterisk.
Total CVEs
51
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH17MEDIUM29LOW2
Vulnerabilities
Page 1 of 3
CVE-2022-26651CRITICALCVSS 9.8v16.82022-04-15
CVE-2022-26651 [CRITICAL] CWE-89 CVE-2022-26651: An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The fun
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.
nvd
CVE-2021-32558HIGHCVSS 7.5v16.82021-07-30
CVE-2021-32558 [HIGH] CWE-74 CVE-2021-32558: An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17
An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.
nvd
CVE-2021-26713MEDIUMCVSS 6.5v16.82021-02-19
CVE-2021-26713 [MEDIUM] CWE-787 CVE-2021-26713: A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before
A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6 allows an authenticated WebRTC client to cause an Asterisk crash by sending multiple hold/unhold requests in quick succession. This is caused by a signedness comparison mismatch.
nvd
CVE-2021-26712HIGHCVSS 7.5v16.82021-02-18
CVE-2021-26712 [HIGH] CVE-2021-26712: Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate secure calls by replaying SRTP packets.
nvd
CVE-2021-26717HIGHCVSS 7.5v16.82021-02-18
CVE-2021-26717 [HIGH] CVE-2021-26717: An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, t
nvd
CVE-2021-26906MEDIUMCVSS 5.9v16.82021-02-18
CVE-2021-26906 [MEDIUM] CWE-404 CVE-2021-26906: An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 1
An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause a
nvd
CVE-2020-28327MEDIUMCVSS 5.3v16.82020-11-06
CVE-2020-28327 [MEDIUM] CWE-404 CVE-2020-28327: A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between the creation of the dialog object,
nvd
CVE-2019-18610HIGHCVSS 8.8v13.21.02019-11-22
CVE-2019-18610 [HIGH] CWE-862 CVE-2019-18610: An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Aste
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.
nvd
CVE-2019-18976HIGHCVSS 7.5v13.212019-11-22
CVE-2019-18976 [HIGH] CWE-476 CVE-2019-18976: An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk t
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940.
nvd
CVE-2019-18790MEDIUMCVSS 6.5v13.21.02019-11-22
CVE-2019-18790 [MEDIUM] CWE-862 CVE-2019-18790: An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that need
nvd
CVE-2019-12827MEDIUMCVSS 6.5v13.212019-07-12
CVE-2019-12827 [MEDIUM] CWE-787 CVE-2019-12827: Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.
Buffer overflow in res_pjsip_messaging in Digium Asterisk versions 13.21-cert3, 13.27.0, 15.7.2, 16.4.0 and earlier allows remote authenticated users to crash Asterisk by sending a specially crafted SIP MESSAGE message.
nvd
CVE-2019-13161MEDIUMCVSS 5.3v1.8.0.0v1.8.1.0+33 more2019-07-12
CVE-2019-13161 [MEDIUM] CWE-476 CVE-2019-13161: An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 1
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerabil
nvd
CVE-2018-17281HIGHCVSS 7.5v11.6v13.1+3 more2018-09-24
CVE-2018-17281 [HIGH] CWE-400 CVE-2018-17281: There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 1
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.
nvd
CVE-2018-12227MEDIUMCVSS 5.3v13.18v13.212018-06-12
CVE-2018-12227 [MEDIUM] CWE-200 CVE-2018-12227: An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x be
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not identified, then a 401 unauthor
nvd
CVE-2018-7284HIGHCVSS 7.5PoCv13.18≤ 13.182018-02-22
CVE-2018-7284 [HIGH] CWE-119 CVE-2018-7284: A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x th
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed
nvd
CVE-2018-7286MEDIUMCVSS 6.5PoC≤ 13.182018-02-22
CVE-2018-7286 [MEDIUM] CVE-2018-7286: An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, a
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.
nvd
CVE-2017-17850HIGHCVSS 7.5v13.1.0v13.82017-12-27
CVE-2017-17850 [HIGH] CWE-20 CVE-2017-17850: An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used, Asterisk would crash. The severity of t
nvd
CVE-2017-17664MEDIUMCVSS 5.9≤ 13.13v13.132017-12-13
CVE-2017-17664 [MEDIUM] CWE-119 CVE-2017-17664: A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4,
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets cause a crash in the RTCP Stack.
nvd
CVE-2017-17090HIGHCVSS 7.5PoC≤ 13.13v13.132017-12-02
CVE-2017-17090 [HIGH] CWE-459 CVE-2017-17090: An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causin
nvd
CVE-2017-16671HIGHCVSS 8.8v13.13.02017-11-09
CVE-2017-16671 [HIGH] CWE-119 CVE-2017-16671: A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1,
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field
nvd
1 / 3Next →