Skip to content
Threat Feed

Tag

Asterisk

4 briefs RSS
high advisory

FreePBX Modules Vulnerable to Unauthenticated RCE and SQL Injection

Multiple critical vulnerabilities have been identified in FreePBX modules, including unauthenticated remote code execution (RCE) in the UCP module, unauthenticated SQL injection in the missedcall module leading to administrator takeover, authenticated command injection in the TTS module, and authenticated RCE in the music module. These flaws affect specific versions of these modules across FreePBX 16 and 17, allowing attackers to execute arbitrary commands, bypass authentication, and gain administrative control.

FreePBX Security-Reporting ucp +7 freepbx rce sql-injection command-injection web-vulnerability asterisk
2r 5t
high threat

Asterisk pjproject Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Asterisk's pjproject to cause denial-of-service or memory corruption, potentially leading to code execution or security bypass.

Asterisk voip denial-of-service memory-corruption
2r 4t
medium advisory

Multiple Vulnerabilities in Asterisk Allow for Remote Denial of Service

Multiple vulnerabilities in Asterisk versions 20.18.x before 20.19.0, 21.12.x before 21.12.2, 22.8.x before 22.9.0, 23.2.x before 23.3.0, certified-asterisk 20.x before 20.7-cert10, and certified-asterisk 22.x before 22.8-cert2 allow a remote attacker to cause a denial of service.

Asterisk versions 20.18.x +5 asterisk voip denial-of-service
2r 1t 3c
critical advisory

Asterisk and Digium Certified Asterisk Vulnerabilities

An authenticated remote attacker can exploit vulnerabilities in Asterisk and Digium Certified Asterisk to achieve arbitrary code execution, denial of service, or information disclosure.

asterisk voip code-execution dos information-disclosure
2r 8t