CVE-2025-54995
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-08-28
Last updated on: 2025-11-03
Assigner: GitHub, Inc.
Description
Description
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sangoma | asterisk | to 18.26.4 (exc) |
| sangoma | certified_asterisk | to 18.9 (exc) |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
| CWE-1286 | The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax. |