VulnerabilityModified
CVE-2025-54995
Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination.
MEDIUM 6.5EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-1286
- Affected
- sangoma/asterisk · sangoma/certified asterisk
- Source
- security-advisories@github.com
References
- https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9Patch
- https://github.com/asterisk/asterisk/commit/eafcd7a451dcd007dddf324ac37dd55a4808338dPatch
- https://github.com/asterisk/asterisk/pull/1405Issue Tracking
- https://github.com/asterisk/asterisk/pull/1406Issue Tracking
- https://github.com/asterisk/asterisk/security/advisories/GHSA-557q-795j-wfx2Exploit, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.