VDB
CVE-2024-42365
CVE-2024-42365
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Asterisk ist eine komplette Open Source Multiprotokoll Telefonanlage (PBX) auf Softwarebasis. Certified Asterisk ist eine komplette Multiprotokoll Telefonanlage (PBX) auf Softwarebasis mit erweitertem Support.
EPSS 31.95% · 96.9th percentile
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N
EPSS Score
31.95%
96.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source | Open Source Asterisk <20.9.2 | |
| Open Source | Open Source Asterisk <18.24.2 | |
| Digium | Digium Certified Asterisk <18.9-cert11 | |
| Debian | Debian Linux | |
| Open Source | Open Source Asterisk <21.4.2 | |
| Fedora | Fedora Linux | |
| Digium | Digium Certified Asterisk <20.7-cert2 |
Timeline
- Jan 21, 1970 Security Advisory
- Aug 8, 2024 CVE Published
- Aug 13, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 14, 2024 EPSS Score
- Nov 25, 2024 EPSS Score
- Dec 2, 2024 PoC Published
- Dec 3, 2024 PoC Published
- Dec 3, 2024 EPSS Score
- Dec 18, 2024 EPSS Score
- Jan 7, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1805.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1805 advisory
- https://github.com/asterisk/asterisk/security/advisories/GHSA-c4cg-9275-6w44 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-42365 advisory
- https://lists.debian.org/debian-lts-announce/2024/10/msg00016.html advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2026-98decbde87 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2026-80b21debe7 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2026-38d71393c1 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-f2281acb03 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-d5cc2324a0 advisory