CVE-2023-37457
Last modified
CVE-2023-37457 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and prior, 20.5.0 and prior, and 21.0.0; as well as ceritifed-asterisk 18.9-cert5 and prior, the 'update' functionality of the PJSIP_HEADER dialplan function can exceed the available buffer space for storing the new value of a header. By doing so this can overwrite memory or cause a crash. This is not externally exploitable, unless dialplan is explicitly written to update a header based on data from an outside source. If the 'update' functionality is not used the vulnerability does not occur. A patch is available at commit a1ca0268254374b515fa5992f01340f7717113fa.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Digium | Asterisk | <= 18.20.0 | — |
| Digium | Asterisk | >= 19.0.0, <= 20.5.0 | — |
| Digium | Asterisk | 21.0.0 | — |
| Sangoma | Certified Asterisk | 13.13.0 | — |
| Sangoma | Certified Asterisk | 16.8.0 | — |
| Sangoma | Certified Asterisk | 18.9 | Cert1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-37457?
How severe is CVE-2023-37457?
How do I fix CVE-2023-37457?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3745A heap-based buffer overflow issue was found in ImageMagick'…5.5
- CVE-2023-37450The issue was addressed with improved checks. This issue is …8.8
- CVE-2023-37453An issue was discovered in the USB subsystem in the Linux ke…4.6
- CVE-2023-37454An issue was discovered in the Linux kernel through 6.4.2. A…5.5
- CVE-2023-37455The permission request prompt from the site in the backgroun…5.4
- CVE-2023-37456The session restore helper crashed whenever there was no par…6.5
- CVE-2023-37459Contiki-NG is an operating system for internet-of-things dev…5.3
- CVE-2023-3746The ActivityPub WordPress plugin before 1.0.0 does not sanit…5.4
- CVE-2023-37460Plexis Archiver is a collection of Plexus components to crea…9.8
- CVE-2023-37461Metersphere is an opensource testing framework. Files upload…9.8
- CVE-2023-37462XWiki Platform is a generic wiki platform offering runtime s…8.8
- CVE-2023-37463cmark-gfm is an extended version of the C reference implemen…7.5
Are you affected by CVE-2023-37457?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
