Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

asterisk

About This Vendor

asterisk is a technology vendor producing software and infrastructure products. As a software provider, asterisk's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of asterisk's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 52 known vulnerabilities from asterisk. This includes 1 critical-severity issue and 24 high-severity issues that represent significant risk. These vulnerabilities affect 19 distinct products across asterisk's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2007 through 2024, indicating decades of continuous security attention and research. Organizations deploying asterisk products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2007-1561 2007-03-21 2025-04-09 - 7.8 Likely
CVE-2007-1594 2007-03-22 2025-04-09 - 7.8 Likely
CVE-2007-1595 2007-03-22 2025-04-09 - 7.5 Likely
CVE-2007-2293 2007-04-26 2025-04-09 - 7.6 Unknown
CVE-2007-2294 2007-04-26 2025-04-09 - 7.8 Likely
CVE-2007-2297 2007-04-26 2025-04-09 - 7.8 Likely
CVE-2007-2488 2007-05-07 2025-04-09 - 10.0 Likely
CVE-2007-3762 2007-07-18 2025-04-09 - 9.3 Likely
CVE-2007-3763 2007-07-18 2025-04-09 - 5.0 Likely
CVE-2007-3764 2007-07-18 2025-04-09 - 5.0 Likely
CVE-2007-3765 2007-07-18 2025-04-09 - 5.0 Likely
CVE-2007-4280 2007-08-09 2025-04-09 - 3.5 Unknown
CVE-2007-4455 2007-08-22 2025-04-09 - 5.0 Likely
CVE-2007-4521 2007-08-28 2025-04-09 - 5.0 Likely
CVE-2007-5488 2007-10-17 2025-04-09 - 7.5 Likely
CVE-2007-5690 2007-10-29 2025-04-09 - 4.6 Unknown
CVE-2007-6430 2007-12-20 2025-04-09 - 4.3 Likely
CVE-2008-0095 2008-01-08 2025-04-09 - 5.0 Likely
CVE-2008-1332 2008-03-20 2025-04-09 - 8.8 Likely
CVE-2008-1333 2008-03-20 2025-04-09 - 5.8 Likely
CVE-2008-1289 2008-03-24 2025-04-09 - 7.5 Likely
CVE-2008-1390 2008-03-24 2025-04-09 - 9.3 Likely
CVE-2008-1897 2008-04-23 2025-04-09 - 4.3 Likely
CVE-2008-1923 2008-04-23 2025-04-09 - 7.1 Likely
CVE-2008-2119 2008-06-04 2025-04-09 - 4.3 Likely
CVE-2008-2543 2008-06-05 2025-04-09 - 5.0 Likely
CVE-2008-3263 2008-07-22 2025-04-09 - 7.8 Likely
CVE-2008-3264 2008-07-24 2025-04-09 - 7.8 Likely
CVE-2008-3903 2008-09-04 2025-04-09 - 3.5 Unknown
CVE-2008-5396 2008-12-09 2025-04-09 - 7.2 Unknown
CVE-2008-5558 2008-12-17 2025-04-09 - 4.3 Likely
CVE-2008-5744 2008-12-26 2025-04-09 - 7.2 Unknown
CVE-2009-0041 2009-01-14 2025-04-09 - 5.0 Likely
CVE-2009-2346 2009-09-08 2025-04-09 - 7.8 Likely
CVE-2010-0441 2010-02-04 2025-04-11 - 5.0 Likely
CVE-2011-4063 2011-10-21 2025-04-11 - 6.8 Likely
CVE-2012-0885 2012-01-25 2025-04-11 - 4.3 Likely
CVE-2012-2414 2012-04-30 2025-04-11 - 6.5 Likely
CVE-2012-2415 2012-04-30 2025-04-11 - 6.5 Likely
CVE-2012-2416 2012-04-30 2025-04-11 - 6.5 Likely
CVE-2012-2948 2012-06-02 2025-04-11 - 4.0 Likely
CVE-2012-2186 2012-08-31 2025-04-11 - 9.0 Likely
CVE-2013-2264 2013-04-01 2025-04-11 - 5.0 Likely
CVE-2013-2685 2013-04-01 2025-04-11 - 7.5 Likely
CVE-2013-2686 2013-04-01 2025-04-11 - 5.0 Likely
CVE-2017-9358 2017-06-02 2025-04-20 7.5 5.0 Likely
CVE-2020-28242 2020-11-06 2024-11-21 6.5 4.0 Likely
CVE-2021-37706 2021-12-22 2025-11-04 7.3 9.3 Likely
CVE-2022-21723 2022-01-27 2025-11-04 9.1 6.4 Likely
CVE-2022-23608 2022-02-22 2025-11-04 8.1 7.5 Likely
CVE-2021-46837 2022-08-30 2024-11-21 6.5 - -
CVE-2024-42365 2024-08-08 2025-11-03 7.4 - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for asterisk by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with asterisk's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.