CVE-2023-37457 is a buffer overflow vulnerability affecting Asterisk and Certified Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0, as well as 18.9-cert5 and prior. The flaw occurs when the PJSIP_HEADER dialplan function's 'update' functionality is used, potentially overwriting memory or causing a crash. Rated as High severity (CVSS 8.2), this vulnerability has a network attack vector and low attack complexity, but it is not externally exploitable unless custom dialplan explicitly updates headers based on external data. The primary impact is a denial of service (crash), with potential for limited integrity impact. Currently, there is no evidence of active exploitation, nor are there public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, aligning with typical trends for most vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.20.0CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
>= 19.0.0, <= 20.5.0CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
21.0.0CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:21.0.0:*:*:*:*:*:*:* | ||
13.13.0CPE matchmatch criteria | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:*:*:*:*:*:*:* | ||
13.13.0CPE matchmatch criteria | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.