← Back

CVE-2025-47779

nvd nist
Published: May 22, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An authenticated attacker can spoof any user identity to send spam messages to the user with their authorization token. Abuse of this security issue allows authenticated attackers to send fake chat messages can be spoofed to appear to come from trusted entities. Even administrators who follow Security best practices and Security Considerations can be impacted. Therefore, abuse can lead to spam and enable social engineering, phishing and similar attacks. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.

Affected (28)

2 products
Asterisk
Certified Asterisk
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Sangoma
Before 18.26.2
From 20.0.0 to 20.14.1
From 21.0.0 to 21.9.1
From 22.0.0 to 22.4.1
Configuration B
24 vulnerable
Vulnerable SoftwareAffected Versions
Sangoma
Before 18.9
Version 18.9
Version 18.9 cert1-rc1
Version 18.9 cert10
Version 18.9 cert11
Version 18.9 cert12
Version 18.9 cert13
Version 18.9 cert1
Version 18.9 cert2
Version 18.9 cert3
Version 18.9 cert4
Version 18.9 cert5
Version 18.9 cert6
Version 18.9 cert7
Version 18.9 cert8-rc1
Version 18.9 cert8-rc2
Version 18.9 cert8
Version 18.9 cert9
Version 20.7 cert1-rc1
Version 20.7 cert1-rc2
Version 20.7 cert1
Version 20.7 cert2
Version 20.7 cert3
Version 20.7 cert4

References (3)

Timeline

No history available yet.