Asterisk Vulnerabilities
The following list includes some of the most critical Asterisk vulnerabilities known to the security community. In any case you find that there is anything missing in this list, please let us know and we will update it as soon as possible.
- Asterisk Manager User Shell Access Permission Escalation Vulnerability
- Asterisk Manager File Descriptor Resource Exhaustion Vulnerability
- Asterisk Invalid Parsing of ACL Rules Can Compromise Security
- Asterisk Dialplan Injection Vulnerability
- Asterisk T.38 Remote Crash Vulnerability
- Asterisk ACL check Vulnerability
- Asterisk IAX2 Call Number Resource Exhaustion
- Asterisk Open Source Crash Vulnerability in RTP stack
- Asterisk Multiple Vulnerabilities
- Asterisk SIP Responses Expose Valid Usernames
- Asterisk IAX \POKE\ Resource Exhaustion
- Ooh323 Channel Driver Crash Vulnerability
- Asterisk Crash Vulnerability In SIP Channel Driver When run in Pedantic Mode
- IAX2 Incomplete 3-Way Handshake (Spoofing)
- Asterisk Multiple RTP Buffer Overflows
- RTP Codec Payload Handling Two Buffer Overflows
- Asterisk SIP Channel Driver Unauthenticated Calls
- Asterisk Logger and Manager Format String Vulnerability
- SIP Channel Driver BYE Vulnerability
- res_config_pgsql SQL Injection Issue
- cdr_pgsql SQL Injection Issue
- Asterisk cdr_addon_mysql SQL Injection Vulnerability
- IMAP Storage Buffer Overflows in Asterisk\s Voicemail
- Resource Exhaustion Vulnerability in Asterisk SIP Channel Driver
- Skinny Channel Driver DoS
- IAX2 Channel Driver Resource Exhaustion Vulnerability
- Stack Buffer Overflow in Asterisk\s IAX2 Channel Driver
- Remote Crash Vulnerability in Asterisk\s IAX2 Channel Driver
- Remote Crash Vulnerability in Asterisk\s Skinny Channel Driver
- Remote Crash Vulnerability in Asterisk\s STUN Implementation
- Multiple Unauthenticated Stack Overflows in Asterisk Chan_sip.c (STP)
- IAX2 Users can Cause Unauthorized Data Disclosure
- Asterisk SIP Denial Of Service Vulnerability (INVITE)
- Asterisk SIP DoS Vulnerability (Empty REGISTER)
- Asterisk Skinny Unauthenticated Heap Overflow
- Asterisk Skinny Heap Overflow (PoC)
- Asterisk Multiple Vulnerabilities (AUEP and Record)
- Asterisk IAX2 Video Frame Buffer Overflow
- Asterisk Manager Interface Buffer Overflow Vulnerability