CVE-2024-35190

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35190
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35190.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-35190
Aliases
  • GHSA-qqxj-v78h-hrf9
Downstream
Published
2024-05-17T16:55:41Z
Modified
2025-10-15T09:42:34.694887Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Asterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests
Details

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

References

Affected packages

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

18.*

18.17.0
18.17.0-rc1
18.17.1
18.18.0
18.18.0-rc1
18.18.1
18.19.0
18.19.0-rc1
18.19.0-rc2
18.20.0
18.20.0-rc1
18.20.1
18.20.2
18.21.0
18.21.0-rc1
18.21.0-rc2
18.22.0
18.22.0-rc1
18.22.0-rc2
18.23.0
18.23.0-rc1

20.*

20.2.0
20.2.0-rc1
20.2.1
20.3.0
20.3.0-rc1
20.3.1
20.4.0
20.4.0-rc1
20.4.0-rc2
20.5.0
20.5.0-rc1
20.5.1
20.5.2
20.6.0
20.6.0-rc1
20.6.0-rc2
20.7.0
20.7.0-rc1
20.7.0-rc2
20.8.0
20.8.0-rc1

21.*

21.0.0
21.0.0-pre1
21.0.0-rc1
21.0.1
21.0.2
21.1.0
21.1.0-rc1
21.1.0-rc2
21.2.0
21.2.0-rc1
21.2.0-rc2
21.3.0
21.3.0-rc1

certified-20.*

certified-20.7-cert1-pre1

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

21.*

21.0.0
21.0.0-pre1
21.0.0-rc1
21.0.1
21.0.2
21.1.0
21.1.0-rc1
21.1.0-rc2
21.2.0
21.2.0-rc1
21.2.0-rc2
21.3.0
21.3.0-rc1

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

20.*

20.2.0
20.2.0-rc1
20.2.1
20.3.0
20.3.0-rc1
20.3.1
20.4.0
20.4.0-rc1
20.4.0-rc2
20.5.0
20.5.0-rc1
20.5.1
20.5.2
20.6.0
20.6.0-rc1
20.6.0-rc2
20.7.0
20.7.0-rc1
20.7.0-rc2
20.8.0
20.8.0-rc1

certified-20.*

certified-20.7-cert1-pre1

Git / github.com/asterisk/asterisk

Affected ranges

Type
GIT
Repo
https://github.com/asterisk/asterisk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

18.*

18.17.0
18.17.0-rc1
18.17.1
18.18.0
18.18.0-rc1
18.18.1
18.19.0
18.19.0-rc1
18.19.0-rc2
18.20.0
18.20.0-rc1
18.20.1
18.20.2
18.21.0
18.21.0-rc1
18.21.0-rc2
18.22.0
18.22.0-rc1
18.22.0-rc2
18.23.0
18.23.0-rc1