VendorsSangomacertified_asteriskall versions
Vulnerabilities

Sangoma Certified Asterisk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-23741
ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
Published 2026-02-06 · Analyzed
8.8EPSS 0.002
CVE-2023-37457
Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'
Published 2023-12-14 · Modified
8.2EPSS 0.011
CVE-2025-47780
cli_permissions.conf: deny option does not work for disallowing shell commands
Published 2025-05-22 · Modified
7.8EPSS 0.003
CVE-2025-1131
Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation
Published 2025-09-23 · Modified
7.8EPSS 0.002
CVE-2026-23740
Asterisk vulnerable to potential privilege escalation
Published 2026-02-06 · Analyzed
7.8EPSS 0.001
CVE-2025-47779
Using malformed From header can forge identity with ";" or NULL in name portion
Published 2025-05-22 · Modified
7.7EPSS 0.005
CVE-2023-49294
Asterisk Path Traversal vulnerability
Published 2023-12-14 · Modified
7.5EPSS 0.456
CVE-2023-49786
Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
Published 2023-12-14 · Modified
7.5EPSS 0.053
CVE-2022-42705
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Published 2022-12-05 · Modified
6.5EPSS 0.013
CVE-2025-54995
Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Published 2025-08-28 · Modified
6.5EPSS 0.005
CVE-2025-49832
Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
Published 2025-08-01 · Analyzed
6.5EPSS 0.005
CVE-2026-23739
Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
Published 2026-02-06 · Analyzed
6.5EPSS 0.002
CVE-2026-23738
The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization
Published 2026-02-06 · Analyzed
6.1EPSS 0.002
CVE-2024-42491
A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used
Published 2024-09-05 · Modified
5.7EPSS 0.006
CVE-2022-42706
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
Published 2022-12-05 · Modified
4.9EPSS 0.011