SIP Authentication Vulnerability in Asterisk Telephony Toolkit
CVE-2025-57767
7.5HIGH
What is CVE-2025-57767?
The Asterisk Telephony Toolkit, prior to versions 20.15.2, 21.10.2, and 22.5.2, contains an authentication vulnerability where improper handling of SIP requests could lead to a segmentation fault. Specifically, if a SIP request includes an Authorization header with an unrecognized realm or an invalid realm without prior proper authentication responses, the get_authorization_header() function fails to validate the integrity of the header, potentially disrupting service. It is crucial for users to upgrade to the patched versions to mitigate these risks, as there are no known workarounds for this issue.
Affected Version(s)
asterisk < 22.5.2 < 22.5.2
asterisk < 21.10.2 < 21.10.2
asterisk < 20.15.2 < 20.15.2