CVE-2025-54995

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
sangomaasterisk
𝑥
< 18.26.4
sangomacertified_asterisk
𝑥
< 18.9
sangomacertified_asterisk
18.9:cert1
sangomacertified_asterisk
18.9:cert1-rc1
sangomacertified_asterisk
18.9:cert10
sangomacertified_asterisk
18.9:cert11
sangomacertified_asterisk
18.9:cert12
sangomacertified_asterisk
18.9:cert13
sangomacertified_asterisk
18.9:cert14
sangomacertified_asterisk
18.9:cert15
sangomacertified_asterisk
18.9:cert16
sangomacertified_asterisk
18.9:cert2
sangomacertified_asterisk
18.9:cert3
sangomacertified_asterisk
18.9:cert4
sangomacertified_asterisk
18.9:cert5
sangomacertified_asterisk
18.9:cert6
sangomacertified_asterisk
18.9:cert7
sangomacertified_asterisk
18.9:cert8
sangomacertified_asterisk
18.9:cert8-rc1
sangomacertified_asterisk
18.9:cert8-rc2
sangomacertified_asterisk
18.9:cert9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
vulnerable
bullseye (security)
1:16.28.0~dfsg-0+deb11u8
fixed
sid
1:22.7.0~dfsg+~cs6.15.60671435-1
fixed