asterisk
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 74 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 21, 2007 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation
Asterisk vulnerable to potential privilege escalation
Asterisk xml.c uses unsafe XML_PARSE_NOENT leading to potential XXE Injection
The Asterisk embedded web server 's /httpstatus page echos user supplied values(cookie and query string) without sanitization
Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation
Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request
Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Asterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
cli_permissions.conf: deny option does not work for disallowing shell commands
Using malformed From header can forge identity with ";" or NULL in name portion
Monitor asterisk in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.