Asterisk
Vendor:
First CVE: Sep 17, 2003 · Active for 22 years
114
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Asterisk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2003
22 years ago
Most Recent CVE
Dec 14, 2023
953 days ago
CVE Severity & Scoring
Asterisk114 CVEs
59%
34%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network47 (41.2%)
Unknown67 (58.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (35.1%)
High7 (6.1%)
Unknown67 (58.8%)
User Interaction
None46 (40.4%)
Unknown67 (58.8%)
Required1 (0.9%)
Privileges Required
Low13 (11.4%)
High0 (0.0%)
None34 (29.8%)
Unknown67 (58.8%)
Top CVEs
Signals from CVEs in this product scope (114 CVEs).
114 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17090HIGH An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the cha | Dec 2, 2017 | 7.5 | 79 | NO | YES |
CVE-2006-5444HIGH Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allow | Oct 23, 2006 | 7.5 | 74 | NO | YES |
CVE-2018-7284HIGH A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBS | Feb 22, 2018 | 7.5 | 67 | NO | YES |
CVE-2017-17850HIGH An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Thos | Dec 27, 2017 | 7.5 | 62 | NO | NO |
CVE-2018-17281HIGH There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk th | Sep 24, 2018 | 7.5 | 54 | NO | NO |
CVE-2018-7286MEDIUM An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated | Feb 22, 2018 | 6.5 | 54 | NO | YES |
CVE-2017-14098HIGH In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to | Sep 2, 2017 | 7.5 | 50 | NO | NO |
CVE-2023-49294HIGH Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cer | Dec 14, 2023 | 7.5 | 43 | NO | NO |
CVE-2019-18610HIGH An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interfac | Nov 22, 2019 | 8.8 | 43 | NO | NO |
CVE-2012-1184HIGH Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of s | Sep 18, 2012 | 7.5 | 41 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (114 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
6.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (114 CVEs).
Media Mentions
Signals from CVEs in this product scope (114 CVEs).
Top CNAs Publishing CVEs For Asterisk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| c.3.7.5 | 1 | 6.0 | 1.5% | 0 | 0 |
| c.3.6.4 | 3 | 5.3 | 2.7% | 0 | 0 |
| c.3.6.3 | 3 | 5.3 | 2.7% | 0 | 0 |
| c.3.6.2 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.3.2 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.2.3 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.2.2 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.1.1 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.1.0 | 6 | 6.1 | 2.9% | 0 | 0 |
| c.3.0 | 9 | 5.8 | 2.9% | 0 | 0 |
| c.2.3 | 7 | 5.6 | 2.9% | 0 | 0 |
| c.1.8.1 | 4 | 6.5 | 2.6% | 0 | 0 |
| c.1.8.0 | 4 | 6.5 | 2.6% | 0 | 0 |
| c.1.6.2 | 4 | 6.5 | 2.6% | 0 | 0 |
| c.1.6.1 | 4 | 6.5 | 2.6% | 0 | 0 |
| c.1.6 | 4 | 6.5 | 2.6% | 0 | 0 |
| c.1.0 | 6 | 6.8 | 2.7% | 0 | 0 |
| c | 2 | 5.0 | 3.5% | 0 | 0 |
| b.2.5.3 | 3 | 5.0 | 2.8% | 0 | 0 |
| b.2.5.2 | 3 | 5.0 | 2.8% | 0 | 0 |