Asterisk

Vendor:

First CVE: Sep 17, 2003 · Active for 22 years

114
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Asterisk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 17, 2003
22 years ago
Most Recent CVE
Dec 14, 2023
953 days ago

CVE Severity & Scoring

Asterisk114 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network47 (41.2%)
Unknown67 (58.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (35.1%)
High7 (6.1%)
Unknown67 (58.8%)
User Interaction
None46 (40.4%)
Unknown67 (58.8%)
Required1 (0.9%)
Privileges Required
Low13 (11.4%)
High0 (0.0%)
None34 (29.8%)
Unknown67 (58.8%)

Top CVEs

Signals from CVEs in this product scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the cha
Dec 2, 20177.579NOYES
Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allow
Oct 23, 20067.574NOYES
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBS
Feb 22, 20187.567NOYES
An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Thos
Dec 27, 20177.562NONO
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk th
Sep 24, 20187.554NONO
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated
Feb 22, 20186.554NOYES
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to
Sep 2, 20177.550NONO
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cer
Dec 14, 20237.543NONO
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interfac
Nov 22, 20198.843NONO
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x before 10.2.1 allows remote attackers to cause a denial of s
Sep 18, 20127.541NOYES

Exploit Exposure

Signals from CVEs in this product scope (114 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
6.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (114 CVEs).

Media Mentions

Signals from CVEs in this product scope (114 CVEs).

Top CNAs Publishing CVEs For Asterisk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
c.3.7.516.01.5%00
c.3.6.435.32.7%00
c.3.6.335.32.7%00
c.3.6.266.12.9%00
c.3.3.266.12.9%00
c.3.2.366.12.9%00
c.3.2.266.12.9%00
c.3.1.166.12.9%00
c.3.1.066.12.9%00
c.3.095.82.9%00
c.2.375.62.9%00
c.1.8.146.52.6%00
c.1.8.046.52.6%00
c.1.6.246.52.6%00
c.1.6.146.52.6%00
c.1.646.52.6%00
c.1.066.82.7%00
c25.03.5%00
b.2.5.335.02.8%00
b.2.5.235.02.8%00