Digium develops telecommunications and voice-communication infrastructure centered on the Asterisk open-source PBX platform and related certified distributions, session-border controllers, and IP phones, products that occupy a distinctive niche in enterprise telephony deployments. The vendor's vulnerability exposure is spread across a modest product portfolio but achieves prominence due to Asterisk's deep embeddedness in production voice systems, where flaws in session handling, protocol parsing, and credential management can affect call routing and media integrity across entire organizations. Recurring weakness classes include buffer-boundary violations, improper input validation, and exposure of sensitive information—patterns reflecting the complexity of real-time protocol state management and the historical memory-safety demands of native C codebases in telecommunications. A moderate share of disclosures acquire public exploit code, and defenders should treat Asterisk advisories as architecturally significant even when individual severity scores do not immediately suggest criticality, since voice infrastructure often remains in service longer than endpoints and exposure depends heavily on network topology and authentication posture. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digium over time
Signals from CVEs in this vendor scope (119 CVEs).
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17090HIGH An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the cha | Dec 2, 2017 | 7.5 | 79 | NO | YES |
CVE-2006-5444HIGH Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allow | Oct 23, 2006 | 7.5 | 74 | NO | YES |
CVE-2018-7284HIGH A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBS | Feb 22, 2018 | 7.5 | 67 | NO | YES |
CVE-2017-17850HIGH An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Thos | Dec 27, 2017 | 7.5 | 62 | NO | NO |
CVE-2018-17281HIGH There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk th | Sep 24, 2018 | 7.5 | 54 | NO | NO |
CVE-2018-7286MEDIUM An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated | Feb 22, 2018 | 6.5 | 54 | NO | YES |
CVE-2017-14098HIGH In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to | Sep 2, 2017 | 7.5 | 50 | NO | NO |
CVE-2023-49294HIGH Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cer | Dec 14, 2023 | 7.5 | 43 | NO | NO |
CVE-2019-18610HIGH An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interfac | Nov 22, 2019 | 8.8 | 43 | NO | NO |
CVE-2012-1184HIGH Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of s | Sep 18, 2012 | 7.5 | 41 | NO | YES |
Signals from CVEs in this vendor scope (119 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digium.
Media articles that mention a CVE ID that affects a product developed by Digium — matched by CVE ID, not by vendor name.