Asterisk is an open-source communications platform widely deployed in VoIP and unified communications environments, spanning server, appliance, and developer-focused product variants that collectively handle call processing, signaling, and media routing across telecommunications infrastructure. Vulnerabilities affecting the vendor cluster around memory-safety and authentication-related weaknesses such as buffer-boundary violations, improper authentication mechanisms, and input-validation gaps that are inherent to a protocol-heavy real-time communications codebase. A meaningful share of the vendor's disclosures reach serious severity, and the exposure has an elevated tendency to acquire public exploit code, reflecting both the attack surface presented by internet-exposed telephony systems and the availability of research tools targeting VoIP stacks. Defenders should track this vendor's security advisories for any internet-facing or externally reachable Asterisk deployments and prioritize authentication and network-segmentation controls; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asterisk over time
Signals from CVEs in this vendor scope (52 CVEs).
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3263HIGH The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.1 | Jul 22, 2008 | 7.8 | 47 | NO | YES |
CVE-2007-2293HIGH Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in Asterisk before 1.4.3 allow remote attackers to execute arbitr | Apr 26, 2007 | 7.6 | 40 | NO | YES |
CVE-2008-0095MEDIUM The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revis | Jan 8, 2008 | 5.0 | 38 | NO | YES |
CVE-2024-42365HIGH Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a | Aug 8, 2024 | 8.8 | 37 | NO | YES |
CVE-2007-3764MEDIUM The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before | Jul 18, 2007 | 5.0 | 37 | NO | YES |
CVE-2007-1561HIGH The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service (crash) via a SIP INVITE message with an SDP containing one | Mar 21, 2007 | 7.8 | 36 | NO | YES |
CVE-2007-3763MEDIUM The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5. | Jul 18, 2007 | 5.0 | 34 | NO | YES |
CVE-2022-23608CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Feb 22, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-37706CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected | Dec 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2008-1289HIGH Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0 | Mar 24, 2008 | 7.5 | 33 | NO | YES |
Signals from CVEs in this vendor scope (52 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asterisk.
Media articles that mention a CVE ID that affects a product developed by Asterisk — matched by CVE ID, not by vendor name.