Sangoma Asterisk vulnerabilities
27 known vulnerabilities affecting sangoma/asterisk.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH7MEDIUM15
Vulnerabilities
Page 2 of 2
CVE-2020-28327MEDIUMCVSS 5.3≥ 13.0.0, < 13.37.1≥ 16.0.0, < 16.14.1+2 more2020-11-06
CVE-2020-28327 [MEDIUM] CWE-404 CVE-2020-28327: A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between the creation of the dialog object,
nvdosv
CVE-2020-28242MEDIUMCVSS 6.5≥ 13.0, < 13.37.1≥ 16.0, < 16.14.1+2 more2020-11-06
CVE-2020-28242 [MEDIUM] CWE-674 CVE-2020-28242: An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x befor
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume mor
nvdosv
CVE-2018-12228MEDIUMCVSS 6.5≥ 15.0, < 15.4.12018-06-12
CVE-2018-12228 [MEDIUM] CWE-835 CVE-2018-12228: An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via T
An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable.
nvd
CVE-2017-9358HIGHCVSS 7.5v13.0.0v13.1.0+24 more2017-06-02
CVE-2017-9358 [HIGH] CWE-835 CVE-2017-9358: A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
nvdosv
CVE-2012-2186CRITICALCVSS 9.0≤ 1.8.15.0≤ 10.7.02012-08-31
CVE-2012-2186 [CRITICAL] CVE-2012-2186: Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 a
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by l
nvdosv
CVE-2012-2948MEDIUMCVSS 4.0≤ 1.8.12.0≤ 10.4.02012-06-02
CVE-2012-2948 [MEDIUM] CWE-399 CVE-2012-2948: chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.1
chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in off-hook mode.
nvdosv
CVE-2009-2346HIGHCVSS 7.8v1.6.1v1.6.1.42009-09-08
CVE-2009-2346 [HIGH] CVE-2009-2346: The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2,
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiatin
nvdosv
← Previous2 / 2