CVE-2024-35190

MEDIUM

Asterisk <18.23.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

Scores

CVSS v3 5.8
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-670 CWE-303 CWE-480
Status published
Products (3)
sangoma/asterisk 18.23.0
sangoma/asterisk 20.8.0
sangoma/asterisk 21.3.0
Published May 17, 2024
Tracked Since Feb 18, 2026