Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

asterisk — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in asterisk, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Asterisk product, classified under the weakness category of Buffer Overflow. It collects public security advisories and vulnerability records, covering the historical timeframe from the product's initial release through the current year. The Asterisk system is widely deployed in enterprise VoIP environments, making it a frequent target for exploit attempts. Here, readers can track the vendor’s security advisories, understand the characteristics of the Buffer Overflow weakness class, and review the complete vulnerability history of the Asterisk product. The data is sourced from public bug trackers and national vulnerability databases, ensuring comprehensive coverage without duplicating specific CVE identifiers. This aggregated view allows security teams to assess risk exposure, identify recurring patterns in patching cycles, and monitor new threat entries related to memory corruption issues. The focus remains on providing a consolidated resource for analyzing how this specific weakness manifests in the Asterisk codebase, supporting both retrospective analysis and ongoing security monitoring.

Vendor: asterisk

CVE ID Title CVSS Severity Published
CVE-2026-23741 ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation CWE-427 - - 2026-02-06
CVE-2026-23740 Asterisk vulnerable to potential privilege escalation CWE-427 - - 2026-02-06
CVE-2026-23739 Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection CWE-611 2.0 Low 2026-02-06
CVE-2026-23738 The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization CWE-79 3.5 Low 2026-02-06
CVE-2025-1131 Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation CWE-427 7.8AI High AI 2025-09-23
CVE-2025-57767 Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request CWE-253 7.5 High 2025-08-28
CVE-2025-54995 Asterisk remotely exploitable leak of RTP UDP ports and internal resources CWE-1286 6.5 Medium 2025-08-28
CVE-2025-49832 Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation CWE-476 6.5 Medium 2025-08-01
CVE-2025-47780 cli_permissions.conf: deny option does not work for disallowing shell commands CWE-78 8.8AI High AI 2025-05-22
CVE-2025-47779 Using malformed From header can forge identity with ";" or NULL in name portion CWE-140 7.7 High 2025-05-22
CVE-2024-42491 A malformed Contact or Record-Route URI in an incoming SIP request can cause Asterisk to crash when res_resolver_unbound is used CWE-252 5.7 Medium 2024-09-05
CVE-2024-42365 Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan CWE-267 7.4 High 2024-08-08
CVE-2024-35190 Asterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests CWE-303 5.8 Medium 2024-05-17
CVE-2023-49786 Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation CWE-703 7.5 High 2023-12-14
CVE-2023-37457 Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update' CWE-120 7.5 High 2023-12-14
CVE-2023-49294 Asterisk Path Traversal vulnerability CWE-22 4.9 Medium 2023-12-14
CVE-2009-3723 Digium Asterisk 安全漏洞 - - 2019-10-29

All 17 known CVE vulnerabilities affecting asterisk with full Chinese analysis, references, and POCs where available.