Description
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.
References (4)
Scores
CVSS v3
5.8
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-670
CWE-303
CWE-480
Status
published
Products (3)
sangoma/asterisk
18.23.0
sangoma/asterisk
20.8.0
sangoma/asterisk
21.3.0
Published
May 17, 2024
Tracked Since
Feb 18, 2026