PT-2024-26370 · Asterisk · Asterisk

Alex2Grad

·

Published

2024-05-17

·

Updated

2025-08-26

·

CVE-2024-35190

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 18.23.1 Asterisk versions prior to 20.8.1 Asterisk versions prior to 21.3.1
Description Asterisk is an open source private branch exchange and telephony toolkit. After an upgrade to 18.23.0, all unauthorized SIP requests are identified as PJSIP Endpoint of the local Asterisk server.
Recommendations For versions prior to 18.23.1, update to version 18.23.1 or later. For versions prior to 20.8.1, update to version 20.8.1 or later. For versions prior to 21.3.1, update to version 21.3.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-35190
GHSA-QQXJ-V78H-HRF9

Affected Products

Asterisk