Certified Asterisk
Vendor:
First CVE: Jun 2, 2012 · Active for 14 years
11
Total CVEs
More Total CVEs than 89% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Certified Asterisk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2012
14 years ago
Most Recent CVE
Aug 8, 2024
715 days ago
CVE Severity & Scoring
Certified Asterisk11 CVEs
45%
27%
27%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (63.6%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High0 (0.0%)
Unknown4 (36.4%)
User Interaction
None7 (63.6%)
Unknown4 (36.4%)
Required0 (0.0%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None4 (36.4%)
Unknown4 (36.4%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-42365HIGH Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 a | Aug 8, 2024 | 8.8 | 37 | NO | YES |
CVE-2022-23608CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Feb 22, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-37706CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected | Dec 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2022-21723CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Jan 27, 2022 | 9.1 | 31 | NO | NO |
CVE-2012-2186HIGH Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk D | Aug 31, 2012 | 9.0 | 27 | NO | NO |
CVE-2017-9358HIGH A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered | Jun 2, 2017 | 7.5 | 25 | NO | NO |
CVE-2021-46837MEDIUM res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash b | Aug 30, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-28242MEDIUM An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If As | Nov 6, 2020 | 6.5 | 23 | NO | NO |
CVE-2012-2948MEDIUM chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 al | Jun 2, 2012 | 4.0 | 17 | NO | NO |
CVE-2013-2686MEDIUM main/http.c in the HTTP server in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1.8.15-cert2; and Asteri | Apr 1, 2013 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Certified Asterisk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 20.7 | 1 | 8.8 | 4.7% | 0 | 1 |
| 18.9 | 1 | 8.8 | 4.7% | 0 | 1 |
| 1.8.15.0 | 2 | 5.0 | 1.7% | 0 | 0 |
| 1.8.15 | 2 | 5.0 | 1.7% | 0 | 0 |
| 1.8.11 | 2 | 7.6 | 3.1% | 0 | 0 |
| 16.8.0 | 5 | 9.0 | 4.2% | 0 | 1 |
| 16.8 | 1 | 8.8 | 4.7% | 0 | 1 |
| 13.13.0 | 2 | 8.2 | 3.8% | 0 | 1 |