VendorsSangomaasteriskall versions
Vulnerabilities

Sangoma Asterisk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2021-37706
Potential integer underflow upon receiving STUN message in PJSIP
Published 2021-12-22 · Modified
9.8EPSS 0.046
CVE-2022-23608
Use after free in PJSIP
Published 2022-02-22 · Modified
9.8EPSS 0.041
CVE-2024-57520
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.
Published 2025-02-05 · Modified
9.8EPSS 0.010
CVE-2022-21723
Out-of-bounds read in multipart parsing in PJSIP
Published 2022-01-27 · Modified
9.1EPSS 0.045
CVE-2012-2186
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by leveraging originate privileges and providing an ExternalIVR value in an AMI Originate action.
Published 2012-08-31 · Modified
9.0EPSS 0.036
CVE-2026-23741
ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
Published 2026-02-06 · Analyzed
8.8EPSS 0.002
CVE-2009-2346
The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263.
Published 2009-09-08 · Modified
7.8EPSS 0.026
CVE-2025-47780
cli_permissions.conf: deny option does not work for disallowing shell commands
Published 2025-05-22 · Modified
7.8EPSS 0.003
CVE-2025-1131
Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation
Published 2025-09-23 · Modified
7.8EPSS 0.002
CVE-2026-23740
Asterisk vulnerable to potential privilege escalation
Published 2026-02-06 · Analyzed
7.8EPSS 0.001
CVE-2025-47779
Using malformed From header can forge identity with ";" or NULL in name portion
Published 2025-05-22 · Modified
7.7EPSS 0.005
CVE-2017-9358
A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).
Published 2017-06-02 · Modified
7.5EPSS 0.028
CVE-2009-3723
asterisk allows calls on prohibited networks
Published 2019-10-29 · Modified
7.5EPSS 0.012
CVE-2022-37325
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
Published 2022-12-05 · Modified
7.5EPSS 0.012
CVE-2025-57767
Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
Published 2025-08-28 · Analyzed
7.5EPSS 0.004
CVE-2018-12228
An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable.
Published 2018-06-12 · Modified
6.8EPSS 0.067
CVE-2020-28242
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume more and more memory since the transaction will never terminate (even if the call is hung up), ultimately leading to a restart or shutdown of Asterisk. Outbound authentication must be configured on the endpoint for this to occur.
Published 2020-11-06 · Modified
6.5EPSS 0.016
CVE-2022-42705
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Published 2022-12-05 · Modified
6.5EPSS 0.013
CVE-2025-54995
Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Published 2025-08-28 · Modified
6.5EPSS 0.005
CVE-2025-49832
Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
Published 2025-08-01 · Analyzed
6.5EPSS 0.005
CVE-2026-23739
Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
Published 2026-02-06 · Analyzed
6.5EPSS 0.002
CVE-2026-23738
The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization
Published 2026-02-06 · Analyzed
6.1EPSS 0.002
CVE-2024-35190
Asterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests
Published 2024-05-17 · Analyzed
5.8EPSS 0.006
CVE-2024-42491
A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used
Published 2024-09-05 · Modified
5.7EPSS 0.006
CVE-2024-53566
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.
Published 2024-12-02 · Analyzed
5.5EPSS 0.003
CVE-2020-28327
A res_pjsip_session crash was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1. and Certified Asterisk before 16.8-cert5. Upon receiving a new SIP Invite, Asterisk did not return the created dialog locked or referenced. This caused a gap between the creation of the dialog object, and its next use by the thread that created it. Depending on some off-nominal circumstances and timing, it was possible for another thread to free said dialog in this gap. Asterisk could then crash when the dialog object, or any of its dependent objects, were dereferenced or accessed next by the initial-creation thread. Note, however, that this crash can only occur when using a connection-oriented protocol (e.g., TCP or TLS, but not UDP) for SIP transport. Also, the remote client must be authenticated, or Asterisk must be configured for anonymous calling.
Published 2020-11-06 · Modified
5.3EPSS 0.020
CVE-2022-42706
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
Published 2022-12-05 · Modified
4.9EPSS 0.011
CVE-2012-2948
chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by closing a connection in off-hook mode.
Published 2012-06-02 · Modified
4.0EPSS 0.021