CVE-2025-47779
Last modified
CVE-2025-47779 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An authenticated attacker can spoof any user identity to send spam messages to the user with their authorization token. Abuse of this security issue allows authenticated attackers to send fake chat messages can be spoofed to appear to come from trusted entities. Even administrators who follow Security best practices and Security Considerations can be impacted. Therefore, abuse can lead to spam and enable social engineering, phishing and similar attacks. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sangoma | Asterisk | < 18.26.2 | — |
| Sangoma | Asterisk | >= 20.0.0, < 20.14.1 | — |
| Sangoma | Asterisk | >= 21.0.0, < 21.9.1 | — |
| Sangoma | Asterisk | >= 22.0.0, < 22.4.1 | — |
| Sangoma | Certified Asterisk | < 18.9 | — |
| Sangoma | Certified Asterisk | 18.9 | — |
| Sangoma | Certified Asterisk | 20.7 | Cert1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-47779?
How severe is CVE-2025-47779?
How do I fix CVE-2025-47779?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47773Combodo iTop is a web based IT service management tool. Vers…6.1
- CVE-2025-47774Vyper is the Pythonic Programming Language for the Ethereum …2.9
- CVE-2025-47775Bullfrog is a GithHb Action to block unauthorized outbound t…8.6
- CVE-2025-47776Mantis Bug Tracker (MantisBT) is an open source issue tracke…9.1
- CVE-2025-477775ire is a cross-platform desktop artificial intelligence ass…9.6
- CVE-2025-47778Sulu is an open-source PHP content management system based o…6.1
- CVE-2025-4778A vulnerability was found in PHPGurukul Park Ticketing Manag…8.8
- CVE-2025-47780Asterisk is an open-source private branch exchange (PBX). Pr…7.8
- CVE-2025-47781Rallly is an open-source scheduling and collaboration tool. …9.8
- CVE-2025-47782motionEye is an online interface for the software motion, a …8.9
- CVE-2025-47783Label Studio is a multi-type data labeling and annotation to…6.1
- CVE-2025-47784Emlog is an open source website building system. Versions 2.…9.8
Are you affected by CVE-2025-47779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
