Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Asterisk

First CVE: Mar 21, 2007Active for: 19 yearsTotal CVEs: 52
43.5
VTI Score
High

Asterisk is an open-source communications platform widely deployed in VoIP and unified communications environments, spanning server, appliance, and developer-focused product variants that collectively handle call processing, signaling, and media routing across telecommunications infrastructure. Vulnerabilities affecting the vendor cluster around memory-safety and authentication-related weaknesses such as buffer-boundary violations, improper authentication mechanisms, and input-validation gaps that are inherent to a protocol-heavy real-time communications codebase. A meaningful share of the vendor's disclosures reach serious severity, and the exposure has an elevated tendency to acquire public exploit code, reflecting both the attack surface presented by internet-exposed telephony systems and the availability of research tools targeting VoIP stacks. Defenders should track this vendor's security advisories for any internet-facing or externally reachable Asterisk deployments and prioritize authentication and network-segmentation controls; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Asterisk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2007
19 years ago
Most Recent CVE
Aug 8, 2024
715 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3263HIGH
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.1
Jul 22, 20087.847NOYES
CVE-2007-2293HIGH
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitr
Apr 26, 20077.640NOYES
CVE-2008-0095MEDIUM
The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revis
Jan 8, 20085.038NOYES
CVE-2024-42365HIGH
Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a
Aug 8, 20248.837NOYES
CVE-2007-3764MEDIUM
The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before
Jul 18, 20075.037NOYES
CVE-2007-1561HIGH
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one
Mar 21, 20077.836NOYES
CVE-2007-3763MEDIUM
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.
Jul 18, 20075.034NOYES
CVE-2022-23608CRITICAL
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions
Feb 22, 20229.833NONO
CVE-2021-37706CRITICAL
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected
Dec 22, 20219.833NONO
CVE-2008-1289HIGH
Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0
Mar 24, 20087.533NOYES
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
48%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (13.5%)
Unknown45 (86.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (13.5%)
High0 (0.0%)
Unknown45 (86.5%)
User Interaction
None7 (13.5%)
Unknown45 (86.5%)
Required0 (0.0%)
Privileges Required
Low3 (5.8%)
High0 (0.0%)
None4 (7.7%)
Unknown45 (86.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
17.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Asterisk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Asterisk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Asterisk's Products

View all 3 CNAs →

Top CWEs