CVE-2024-35190
MEDIUMAsterisk <18.23.0 - Info Disclosure
Title source: llmDescription
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.
Scores
CVSS v3
5.8
EPSS
0.0033
EPSS Percentile
55.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Classification
CWE
CWE-670
CWE-303
CWE-480
Status
published
Affected Products (3)
sangoma/asterisk
sangoma/asterisk
sangoma/asterisk
Timeline
Published
May 17, 2024
Tracked Since
Feb 18, 2026