PT-2024-26370 · Asterisk · Asterisk
Alex2Grad
·
Published
2024-05-17
·
Updated
2025-08-26
·
CVE-2024-35190
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asterisk versions prior to 18.23.1
Asterisk versions prior to 20.8.1
Asterisk versions prior to 21.3.1
Description
Asterisk is an open source private branch exchange and telephony toolkit. After an upgrade to 18.23.0, all unauthorized SIP requests are identified as PJSIP Endpoint of the local Asterisk server.
Recommendations
For versions prior to 18.23.1, update to version 18.23.1 or later.
For versions prior to 20.8.1, update to version 20.8.1 or later.
For versions prior to 21.3.1, update to version 21.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asterisk