ID

VAR-202508-3383


CVE

CVE-2025-57767


DESCRIPTION

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Authenticate header, or an Authorization header with an incorrect realm was received without a previous 401 response being sent, the get_authorization_header() function in res_pjsip_authenticator_digest will return a NULL. This wasn't being checked before attempting to get the digest algorithm from the header which causes a SEGV. This issue has been patched in versions 20.15.2, 21.10.2, and 22.5.2. There are no workarounds.

Trust: 1.0

sources: NVD: CVE-2025-57767

AFFECTED PRODUCTS

vendor:sangomamodel:asteriskscope:ltversion:22.5.2

Trust: 1.0

vendor:sangomamodel:asteriskscope:ltversion:21.10.2

Trust: 1.0

vendor:sangomamodel:asteriskscope:gteversion:22.0.0

Trust: 1.0

vendor:sangomamodel:asteriskscope:gteversion:21.0.0

Trust: 1.0

vendor:sangomamodel:asteriskscope:ltversion:20.15.2

Trust: 1.0

sources: NVD: CVE-2025-57767

CVSS

SEVERITY

CVSSV2

CVSSV3

security-advisories@github.com: CVE-2025-57767
value: HIGH

Trust: 1.0

security-advisories@github.com: CVE-2025-57767
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-57767

PROBLEMTYPE DATA

problemtype:CWE-253

Trust: 1.0

sources: NVD: CVE-2025-57767

EXTERNAL IDS

db:NVDid:CVE-2025-57767

Trust: 1.0

sources: NVD: CVE-2025-57767

REFERENCES

url:https://github.com/asterisk/asterisk/commit/02993717b08f899d4aca9888062f35dfb198584f

Trust: 1.0

url:https://github.com/asterisk/asterisk/security/advisories/ghsa-64qc-9x89-rx5j

Trust: 1.0

url:https://github.com/asterisk/asterisk/pull/1407

Trust: 1.0

sources: NVD: CVE-2025-57767

SOURCES

db:NVDid:CVE-2025-57767

LAST UPDATE DATE

2025-11-18T11:35:39.801000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-57767date:2025-10-20T17:51:12.860

SOURCES RELEASE DATE

db:NVDid:CVE-2025-57767date:2025-08-28T16:15:35.410