CVE-2024-35190
Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.57%
- CWE
- CWE-303, CWE-480, CWE-670
- Published
- 2024-05-17
- Last modified
- 2026-03-13
Affected products
- asterisk asterisk
- asterisk asterisk
- asterisk asterisk
Weakness type
Related vulnerabilities
- CVE-2026-78629 — Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling
- CVE-2026-9854 — A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools...
- CVE-2026-9853 — A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the...
- CVE-2026-49467 — TOTP enrollment hijack: password gate skipped due to unawaited promise
- CVE-2026-66411 — DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket...
- CVE-2026-11430 — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-59309 — vCenter authentication-bypass vulnerability