CVE-2024-35190

MEDIUM

Asterisk <18.23.0 - Info Disclosure

Title source: llm

Description

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

Scores

CVSS v3 5.8
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Classification

CWE
CWE-670 CWE-303 CWE-480
Status published

Affected Products (3)

sangoma/asterisk
sangoma/asterisk
sangoma/asterisk

Timeline

Published May 17, 2024
Tracked Since Feb 18, 2026