VDB
CVE-2022-23608
CVE-2022-23608
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Asterisk ist eine komplette Open Source Multiprotokoll Telefonanlage (PBX) auf Softwarebasis. Certified Asterisk ist eine komplette Multiprotokoll Telefonanlage (PBX) auf Softwarebasis mit erweitertem Support.
EPSS 4.06% · 89.9th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
4.06%
89.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digium | Digium Certified Asterisk <16.8-cert13 | |
| Ubuntu | Ubuntu Linux | |
| Open Source | Open Source Asterisk <19.2.1 | |
| Debian | Debian Linux | |
| Open Source | Open Source Asterisk <18.10.1 | |
| Open Source | Open Source Asterisk <16.24.1 |
Timeline
- Feb 22, 2022 CVE Published
- Feb 23, 2022 EPSS Score
- Apr 16, 2022 EPSS Score
- Jul 30, 2022 EPSS Score
- Sep 20, 2022 EPSS Score
- Nov 11, 2022 EPSS Score
- Jan 2, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 16, 2023 EPSS Score
- Jun 7, 2023 EPSS Score
- Jul 29, 2023 EPSS Score
- Nov 10, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-2108.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-2108 advisory
- https://downloads.asterisk.org/pub/security/AST-2022-004.html advisory
- https://downloads.asterisk.org/pub/security/AST-2022-005.html advisory
- https://downloads.asterisk.org/pub/security/AST-2022-006.html advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html advisory
- https://lists.debian.org/debian-security-announce/2022/msg00256.html advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html advisory
- https://ubuntu.com/security/notices/USN-8122-1 advisory