← Back

CVE-2025-54995

nvd nist
Published: Aug 28, 2025Modified: Nov 3, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

Affected (21)

2 products
Asterisk
Certified Asterisk
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Before 18.26.4
Sangoma
Before 18.9
Version 18.9 cert1-rc1
Version 18.9 cert10
Version 18.9 cert11
Version 18.9 cert12
Version 18.9 cert13
Version 18.9 cert14
Version 18.9 cert15
Version 18.9 cert16
Version 18.9 cert1
Version 18.9 cert2
Version 18.9 cert3
Version 18.9 cert4
Version 18.9 cert5
Version 18.9 cert6
Version 18.9 cert7
Version 18.9 cert8-rc1
Version 18.9 cert8-rc2
Version 18.9 cert8
Version 18.9 cert9

References (6)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.