PT-2025-31568 · Asterisk+2 · Asterisk+2

Wtfismyip

·

Published

2025-07-31

·

Updated

2025-09-29

·

CVE-2025-49832

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Asterisk versions 18.26.2 and earlier Asterisk versions 20.00.0 through 20.15.0 Asterisk version 20.7-cert6 Asterisk version 21.00.0 Asterisk versions 22.00.0 through 22.5.0
Description Asterisk is an open source private branch exchange and telephony toolkit. A remote Denial of Service (DoS) and potential Remote Code Execution (RCE) condition exists in asterisk/res/res stir shaken/verification.c when an attacker can set an arbitrary Identity header, or STIR/SHAKEN is enabled with verification set in the associated SIP profile.
Recommendations Update to Asterisk version 18.26.3 or later. Update to Asterisk version 20.7-cert6 or later. Update to Asterisk version 20.15.1 or later. Update to Asterisk version 21.10.1 or later. Update to Asterisk version 22.5.1 or later.

Exploit

Fix

DoS

RCE

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2025-11102
CVE-2025-49832
GHSA-MRQ5-74J5-F5CR

Affected Products

Alt Linux
Asterisk
Debian