Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 20 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Sangoma Sangoma asterisk Sangoma certified Asterisk | |
| CPEs | cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert16:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:* cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:* | |
| Vendors & Products | Sangoma Sangoma asterisk Sangoma certified Asterisk | 
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Asterisk Asterisk asterisk | |
| Vendors & Products | Asterisk Asterisk asterisk | 
Thu, 28 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 28 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17. | |
| Title | Asterisk remotely exploitable leak of RTP UDP ports and internal resources | |
| Weaknesses | CWE-1286 CWE-400 | |
| References |  | 
 | 
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-28T15:08:04.468Z
Updated: 2025-08-28T18:54:20.465Z
Reserved: 2025-08-04T17:34:24.420Z
Link: CVE-2025-54995
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-28T18:54:17.173Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-08-28T15:16:02.500
Modified: 2025-10-20T15:26:37.117
Link: CVE-2025-54995
 Redhat
                        Redhat
                    No data.