CVE-2024-35190

MEDIUM

Asterisk <18.23.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

References (4)

Core 4

Scores

CVSS v3 5.8
EPSS 0.0057
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-303 CWE-480 CWE-670
Status published
Products (3)
sangoma/asterisk 18.23.0
sangoma/asterisk 20.8.0
sangoma/asterisk 21.3.0
Published May 17, 2024
Tracked Since Feb 18, 2026