VendorsSangomacertified_asterisk20.7
Vulnerabilities

Sangoma Certified Asterisk 20.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-23741
ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
Published 2026-02-06 · Analyzed
8.8EPSS 0.002
CVE-2025-47780
cli_permissions.conf: deny option does not work for disallowing shell commands
Published 2025-05-22 · Modified
7.8EPSS 0.003
CVE-2025-1131
Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation
Published 2025-09-23 · Modified
7.8EPSS 0.002
CVE-2026-23740
Asterisk vulnerable to potential privilege escalation
Published 2026-02-06 · Analyzed
7.8EPSS 0.001
CVE-2025-47779
Using malformed From header can forge identity with ";" or NULL in name portion
Published 2025-05-22 · Modified
7.7EPSS 0.005
CVE-2025-49832
Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
Published 2025-08-01 · Analyzed
6.5EPSS 0.005
CVE-2026-23739
Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
Published 2026-02-06 · Analyzed
6.5EPSS 0.002
CVE-2026-23738
The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization
Published 2026-02-06 · Analyzed
6.1EPSS 0.002
CVE-2024-42491
A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used
Published 2024-09-05 · Modified
5.7EPSS 0.006