Skip to content
Noroxi

freeswitch records

21 published records for vendor freeswitch.

All records

21 records
  • FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

    CriticalCVSS 9.8WeaponizedEPSS 29%

    freeswitch · freeswitchDec 1, 2019

  • FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read

    CriticalCVSS 9.8No exploitEPSS 1%

    freeswitch · freeswitchJun 9, 2026

  • FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing

    CriticalCVSS 9.1No exploitEPSS 0%

    freeswitch · freeswitchJun 9, 2026

  • CVE-2015-7392
    31Monitor

    Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows

    HighCVSS 7.5No exploitEPSS 5%

    freeswitch · freeswitchOct 5, 2015

  • FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing

    HighCVSS 7.5Proof of conceptEPSS 4%

    freeswitch · freeswitchOct 25, 2021

  • FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/sy

    HighCVSS 7.5Proof of conceptEPSS 3%

    freeswitch · freeswitchDec 6, 2018

  • FreeSWITCH susceptible to Denial of Service via invalid SRTP packets

    HighCVSS 7.5No exploitEPSS 3%

    freeswitch · freeswitchOct 25, 2021

  • FreeSWITCH susceptible to Denial of Service via SIP flooding

    HighCVSS 7.5No exploitEPSS 2%

    freeswitch · freeswitchOct 25, 2021

  • FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID

    HighCVSS 7.5No exploitEPSS 1%

    freeswitch · freeswitchSep 15, 2023

  • FreeSWITCH vulnerable to SIP digest leak for configured gateways

    HighCVSS 7.5No exploitEPSS 1%

    freeswitch · freeswitchOct 26, 2021

  • FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames

    HighCVSS 7.5No exploitEPSS 1%

    freeswitch · freeswitchJun 9, 2026

  • FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON

    HighCVSS 7.5No exploitEPSS 1%

    freeswitch · freeswitchJun 9, 2026

  • FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing

    HighCVSS 7.5No exploitEPSS 0%

    freeswitch · freeswitchJun 9, 2026

  • Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion

    HighCVSS 7.5No exploitEPSS 0%

    freeswitch · freeswitchJun 9, 2026

  • CVE-2013-2238
    28Monitor

    Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a

    MediumCVSS 6.8No exploitEPSS 3%

    freeswitch · freeswitchSep 30, 2013

  • FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names

    MediumCVSS 6.5No exploitEPSS 1%

    freeswitch · freeswitchSep 15, 2023

  • FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation

    MediumCVSS 5.9No exploitEPSS 1%

    freeswitch · freeswitchDec 27, 2023

  • FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default

    MediumCVSS 5.3No exploitEPSS 2%

    freeswitch · freeswitchOct 26, 2021

  • FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`

    MediumCVSS 5.3No exploitEPSS 1%

    freeswitch · freeswitchJun 9, 2026

  • FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat

    MediumCVSS 5.3No exploitEPSS 0%

    freeswitch · freeswitchJun 9, 2026

  • FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`

    MediumCVSS 4.3No exploitEPSS 0%

    freeswitch · freeswitchJun 9, 2026