Description
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Attack Vector
- network
- Complexity
- low
- Privileges
- none
- User Action
- none
- Scope
- changed
- Confidentiality
- low
- Integrity
- none
- Availability
- none
- Weaknesses
- CWE-303CWE-480CWE-670
Metadata
- Primary Vendor
- SANGOMA
- Published
- 5/17/2024
- Last Modified
- 8/26/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
sangoma : asterisksangoma : asterisksangoma : asterisk
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.