Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a denial of service (resource consumption) by making anonymous calls from multiple sources and consequently adding many entries to the device state cache.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade asterisk | Nov 8, 2019 | Jan 4, 2013 |
| Debian | — | Upgrade asterisk | Jul 30, 2024 | Jan 4, 2013 |
| Freebsd | — | Upgrade asterisk10Upgrade asterisk11Upgrade asterisk18 | Dec 10, 2025 | Jan 3, 2013 |
| Gentoo Linux | — | Upgrade net-misc/asterisk. | Oct 30, 2017 | Jan 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub