Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
Metrics
Affected Vendors & Products
References
History
Thu, 28 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Asterisk
Asterisk asterisk |
|
Vendors & Products |
Asterisk
Asterisk asterisk |
Thu, 28 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 28 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17. | |
Title | Asterisk remotely exploitable leak of RTP UDP ports and internal resources | |
Weaknesses | CWE-1286 CWE-400 |
|
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-28T15:08:04.468Z
Updated: 2025-08-28T18:54:20.465Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54995

Updated: 2025-08-28T18:54:17.173Z

Status : Received
Published: 2025-08-28T15:16:02.500
Modified: 2025-08-28T15:16:02.500
Link: CVE-2025-54995

No data.