freeswitch records
21 published records for vendor freeswitch.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.8%
- Pre-auth RCE
- 3
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication4
- CWE-20 Improper Input Validation3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-703 Improper Check or Handling of Exceptional Conditions1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2019-19492Weaponized | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.freeswitch · freeswitch · CWE-798 | Critical9.8 | — | 29.4% | Dec 1, 2019 |
39Monitor | CVE-2026-49841No exploit | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body readfreeswitch · freeswitch · CWE-122 | Critical9.8 | — | 0.6% | Jun 9, 2026 |
36Monitor | CVE-2026-49840No exploit | FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingfreeswitch · freeswitch · CWE-20 | Critical9.1 | — | 0.5% | Jun 9, 2026 |
31Monitor | CVE-2015-7392No exploit | Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allowsfreeswitch · freeswitch · CWE-119 | High7.5 | — | 4.7% | Oct 5, 2015 |
31Monitor | CVE-2021-37624Proof of concept | FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingfreeswitch · freeswitch · CWE-287 | High7.5 | — | 3.7% | Oct 25, 2021 |
31Monitor | CVE-2018-19911Proof of concept | FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/syfreeswitch · freeswitch · CWE-77 | High7.5 | — | 2.7% | Dec 6, 2018 |
31Monitor | CVE-2021-41105No exploit | FreeSWITCH susceptible to Denial of Service via invalid SRTP packetsfreeswitch · freeswitch · CWE-20 | High7.5 | — | 2.5% | Oct 25, 2021 |
30Monitor | CVE-2021-41145No exploit | FreeSWITCH susceptible to Denial of Service via SIP floodingfreeswitch · freeswitch · CWE-400 | High7.5 | — | 1.7% | Oct 25, 2021 |
30Monitor | CVE-2023-40018No exploit | FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component IDfreeswitch · freeswitch · CWE-787 | High7.5 | — | 1.0% | Sep 15, 2023 |
30Monitor | CVE-2021-41158No exploit | FreeSWITCH vulnerable to SIP digest leak for configured gatewaysfreeswitch · freeswitch · CWE-200 | High7.5 | — | 0.8% | Oct 26, 2021 |
30Monitor | CVE-2026-49842No exploit | FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test framesfreeswitch · freeswitch · CWE-400 | High7.5 | — | 0.6% | Jun 9, 2026 |
30Monitor | CVE-2026-49847No exploit | FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSONfreeswitch · freeswitch · CWE-674 | High7.5 | — | 0.5% | Jun 9, 2026 |
30Monitor | CVE-2026-49475No exploit | FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsingfreeswitch · freeswitch · CWE-20 | High7.5 | — | 0.5% | Jun 9, 2026 |
30Monitor | CVE-2026-45771No exploit | Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansionfreeswitch · freeswitch · CWE-776 | High7.5 | — | 0.5% | Jun 9, 2026 |
28Monitor | CVE-2013-2238No exploit | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a freeswitch · freeswitch · CWE-119 | Medium6.8 | — | 2.7% | Sep 30, 2013 |
26Monitor | CVE-2023-40019No exploit | FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec namesfreeswitch · freeswitch · CWE-770 | Medium6.5 | — | 0.9% | Sep 15, 2023 |
23Monitor | CVE-2023-51443No exploit | FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiationfreeswitch · freeswitch · CWE-703 | Medium5.9 | — | 1.5% | Dec 27, 2023 |
22Monitor | CVE-2021-41157No exploit | FreeSWITCH does not authenticate SIP SUBSCRIBE requests by defaultfreeswitch · freeswitch · CWE-287 | Medium5.3 | — | 1.7% | Oct 26, 2021 |
21Monitor | CVE-2026-49843No exploit | FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`freeswitch · freeswitch · CWE-287 | Medium5.3 | — | 0.5% | Jun 9, 2026 |
21Monitor | CVE-2026-49472No exploit | FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpatfreeswitch · freeswitch · CWE-116 | Medium5.3 | — | 0.4% | Jun 9, 2026 |
17Monitor | CVE-2026-49848No exploit | FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`freeswitch · freeswitch · CWE-287 | Medium4.3 | — | 0.3% | Jun 9, 2026 |
- CVE-2019-1949248Plan
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
CriticalCVSS 9.8WeaponizedEPSS 29%freeswitch · freeswitchDec 1, 2019
- CVE-2026-4984139Monitor
FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CriticalCVSS 9.8No exploitEPSS 1%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4984036Monitor
FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
CriticalCVSS 9.1No exploitEPSS 0%freeswitch · freeswitchJun 9, 2026
- CVE-2015-739231Monitor
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows
HighCVSS 7.5No exploitEPSS 5%freeswitch · freeswitchOct 5, 2015
- CVE-2021-3762431Monitor
FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
HighCVSS 7.5Proof of conceptEPSS 4%freeswitch · freeswitchOct 25, 2021
- CVE-2018-1991131Monitor
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/sy
HighCVSS 7.5Proof of conceptEPSS 3%freeswitch · freeswitchDec 6, 2018
- CVE-2021-4110531Monitor
FreeSWITCH susceptible to Denial of Service via invalid SRTP packets
HighCVSS 7.5No exploitEPSS 3%freeswitch · freeswitchOct 25, 2021
- CVE-2021-4114530Monitor
FreeSWITCH susceptible to Denial of Service via SIP flooding
HighCVSS 7.5No exploitEPSS 2%freeswitch · freeswitchOct 25, 2021
- CVE-2023-4001830Monitor
FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID
HighCVSS 7.5No exploitEPSS 1%freeswitch · freeswitchSep 15, 2023
- CVE-2021-4115830Monitor
FreeSWITCH vulnerable to SIP digest leak for configured gateways
HighCVSS 7.5No exploitEPSS 1%freeswitch · freeswitchOct 26, 2021
- CVE-2026-4984230Monitor
FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
HighCVSS 7.5No exploitEPSS 1%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4984730Monitor
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
HighCVSS 7.5No exploitEPSS 1%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4947530Monitor
FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
HighCVSS 7.5No exploitEPSS 0%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4577130Monitor
Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
HighCVSS 7.5No exploitEPSS 0%freeswitch · freeswitchJun 9, 2026
- CVE-2013-223828Monitor
Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a
MediumCVSS 6.8No exploitEPSS 3%freeswitch · freeswitchSep 30, 2013
- CVE-2023-4001926Monitor
FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names
MediumCVSS 6.5No exploitEPSS 1%freeswitch · freeswitchSep 15, 2023
- CVE-2023-5144323Monitor
FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
MediumCVSS 5.9No exploitEPSS 1%freeswitch · freeswitchDec 27, 2023
- CVE-2021-4115722Monitor
FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
MediumCVSS 5.3No exploitEPSS 2%freeswitch · freeswitchOct 26, 2021
- CVE-2026-4984321Monitor
FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`
MediumCVSS 5.3No exploitEPSS 1%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4947221Monitor
FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat
MediumCVSS 5.3No exploitEPSS 0%freeswitch · freeswitchJun 9, 2026
- CVE-2026-4984817Monitor
FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`
MediumCVSS 4.3No exploitEPSS 0%freeswitch · freeswitchJun 9, 2026