PT-2025-35096 · Asterisk+2 · Asterisk+2
Alexat
·
Published
2025-08-28
·
Updated
2025-11-06
·
CVE-2025-54995
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Asterisk versions prior to 18.26.4
Asterisk versions prior to 18.9-cert17
Description
Asterisk, an open source private branch exchange and telephony toolkit, is susceptible to resource exhaustion due to a lack of session termination. This can lead to leaks of RTP UDP ports and internal resources.
Recommendations
Update Asterisk to version 18.26.4 or later.
Update Asterisk to version 18.9-cert17 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asterisk
Debian
Red Os