digium
Security Risk Profile
47
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 121 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 12, 2003 to present
121
Total CVEs
47
Critical+High
0
Exploited
15
Unpatched
Threat Assessment
Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
15
Critical/High
Risk Level
47/100
medium
Severity Distribution
Critical
7High
40Medium
68Low
6Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
26
2
Null Pointer Dereference
16
3
Input Validation
14
4
Infoleak
7
5
SQL Injection
4
Most Affected Products
1. Asterisk5413
2. Digium Asterisk1255
3. Digium Asterisk Appliance Developer Kit490
4. Digium Certified Asterisk378
5. Asterisk Open Source149
Recent Vulnerabilities
See more →CVE-2023-49786
CVSS 7.5high
Asterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
12/14/2023
CVE-2023-37457
CVSS 8.2high
Asterisk's PJSIP_HEADER dialplan function can overwrite memory/cause crash when using 'update'
12/14/2023
CVE-2023-49294
CVSS 7.5high
Asterisk Path Traversal vulnerability
12/14/2023
CVE-2021-46837
CVSS 6.5medium
8/25/2022
CVE-2022-26498
CVSS 7.5high
4/15/2022
CVE-2022-26499
CVSS 9.1critical
4/15/2022
CVE-2022-26651
CVSS 9.8critical
4/15/2022
CVE-2021-32558
CVSS 7.5high
7/27/2021
CVE-2021-31878
CVSS 6.5medium
7/27/2021
CVE-2021-26713
CVSS 6.5medium
2/19/2021🔧 No Patch
Monitor digium in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.