Записи freeswitch
21 опубликованных записей вендора freeswitch.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 4,8 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 71,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication4
- CWE-20 Improper Input Validation3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-703 Improper Check or Handling of Exceptional Conditions1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2019-19492Готовый эксплойт | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.freeswitch · freeswitch · CWE-798 | Критическая9,8 | — | 29,4 % | 1 дек. 2019 г. |
39Наблюдать | CVE-2026-49841Эксплойта нет | FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body readfreeswitch · freeswitch · CWE-122 | Критическая9,8 | — | 0,6 % | 9 июн. 2026 г. |
36Наблюдать | CVE-2026-49840Эксплойта нет | FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsingfreeswitch · freeswitch · CWE-20 | Критическая9,1 | — | 0,5 % | 9 июн. 2026 г. |
31Наблюдать | CVE-2015-7392Эксплойта нет | Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allowsfreeswitch · freeswitch · CWE-119 | Высокая7,5 | — | 4,7 % | 5 окт. 2015 г. |
31Наблюдать | CVE-2021-37624Proof of concept | FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofingfreeswitch · freeswitch · CWE-287 | Высокая7,5 | — | 3,7 % | 25 окт. 2021 г. |
31Наблюдать | CVE-2018-19911Proof of concept | FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/syfreeswitch · freeswitch · CWE-77 | Высокая7,5 | — | 2,7 % | 6 дек. 2018 г. |
31Наблюдать | CVE-2021-41105Эксплойта нет | FreeSWITCH susceptible to Denial of Service via invalid SRTP packetsfreeswitch · freeswitch · CWE-20 | Высокая7,5 | — | 2,5 % | 25 окт. 2021 г. |
30Наблюдать | CVE-2021-41145Эксплойта нет | FreeSWITCH susceptible to Denial of Service via SIP floodingfreeswitch · freeswitch · CWE-400 | Высокая7,5 | — | 1,7 % | 25 окт. 2021 г. |
30Наблюдать | CVE-2023-40018Эксплойта нет | FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component IDfreeswitch · freeswitch · CWE-787 | Высокая7,5 | — | 1,0 % | 15 сент. 2023 г. |
30Наблюдать | CVE-2021-41158Эксплойта нет | FreeSWITCH vulnerable to SIP digest leak for configured gatewaysfreeswitch · freeswitch · CWE-200 | Высокая7,5 | — | 0,8 % | 26 окт. 2021 г. |
30Наблюдать | CVE-2026-49842Эксплойта нет | FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test framesfreeswitch · freeswitch · CWE-400 | Высокая7,5 | — | 0,6 % | 9 июн. 2026 г. |
30Наблюдать | CVE-2026-49847Эксплойта нет | FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSONfreeswitch · freeswitch · CWE-674 | Высокая7,5 | — | 0,5 % | 9 июн. 2026 г. |
30Наблюдать | CVE-2026-49475Эксплойта нет | FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsingfreeswitch · freeswitch · CWE-20 | Высокая7,5 | — | 0,5 % | 9 июн. 2026 г. |
30Наблюдать | CVE-2026-45771Эксплойта нет | Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansionfreeswitch · freeswitch · CWE-776 | Высокая7,5 | — | 0,5 % | 9 июн. 2026 г. |
28Наблюдать | CVE-2013-2238Эксплойта нет | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a freeswitch · freeswitch · CWE-119 | Средняя6,8 | — | 2,7 % | 30 сент. 2013 г. |
26Наблюдать | CVE-2023-40019Эксплойта нет | FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec namesfreeswitch · freeswitch · CWE-770 | Средняя6,5 | — | 0,9 % | 15 сент. 2023 г. |
23Наблюдать | CVE-2023-51443Эксплойта нет | FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiationfreeswitch · freeswitch · CWE-703 | Средняя5,9 | — | 1,5 % | 27 дек. 2023 г. |
22Наблюдать | CVE-2021-41157Эксплойта нет | FreeSWITCH does not authenticate SIP SUBSCRIBE requests by defaultfreeswitch · freeswitch · CWE-287 | Средняя5,3 | — | 1,7 % | 26 окт. 2021 г. |
21Наблюдать | CVE-2026-49843Эксплойта нет | FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`freeswitch · freeswitch · CWE-287 | Средняя5,3 | — | 0,5 % | 9 июн. 2026 г. |
21Наблюдать | CVE-2026-49472Эксплойта нет | FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpatfreeswitch · freeswitch · CWE-116 | Средняя5,3 | — | 0,4 % | 9 июн. 2026 г. |
17Наблюдать | CVE-2026-49848Эксплойта нет | FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`freeswitch · freeswitch · CWE-287 | Средняя4,3 | — | 0,3 % | 9 июн. 2026 г. |
- CVE-2019-1949248В плане
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
КритическаяCVSS 9,8Готовый эксплойтEPSS 29 %freeswitch · freeswitch1 дек. 2019 г.
- CVE-2026-4984139Наблюдать
FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4984036Наблюдать
FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2015-739231Наблюдать
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %freeswitch · freeswitch5 окт. 2015 г.
- CVE-2021-3762431Наблюдать
FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %freeswitch · freeswitch25 окт. 2021 г.
- CVE-2018-1991131Наблюдать
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/sy
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %freeswitch · freeswitch6 дек. 2018 г.
- CVE-2021-4110531Наблюдать
FreeSWITCH susceptible to Denial of Service via invalid SRTP packets
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeswitch · freeswitch25 окт. 2021 г.
- CVE-2021-4114530Наблюдать
FreeSWITCH susceptible to Denial of Service via SIP flooding
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %freeswitch · freeswitch25 окт. 2021 г.
- CVE-2023-4001830Наблюдать
FreeSWITCH allows remote users to trigger out of bounds write by offering an ICE candidate with unknown component ID
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %freeswitch · freeswitch15 сент. 2023 г.
- CVE-2021-4115830Наблюдать
FreeSWITCH vulnerable to SIP digest leak for configured gateways
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %freeswitch · freeswitch26 окт. 2021 г.
- CVE-2026-4984230Наблюдать
FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4984730Наблюдать
FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4947530Наблюдать
FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4577130Наблюдать
Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2013-223828Наблюдать
Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a
СредняяCVSS 6,8Эксплойта нетEPSS 3 %freeswitch · freeswitch30 сент. 2013 г.
- CVE-2023-4001926Наблюдать
FreeSWITCH allows authorized users to cause a denial of service attack by sending re-INVITE with SDP containing duplicate codec names
СредняяCVSS 6,5Эксплойта нетEPSS 1 %freeswitch · freeswitch15 сент. 2023 г.
- CVE-2023-5144323Наблюдать
FreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
СредняяCVSS 5,9Эксплойта нетEPSS 1 %freeswitch · freeswitch27 дек. 2023 г.
- CVE-2021-4115722Наблюдать
FreeSWITCH does not authenticate SIP SUBSCRIBE requests by default
СредняяCVSS 5,3Эксплойта нетEPSS 2 %freeswitch · freeswitch26 окт. 2021 г.
- CVE-2026-4984321Наблюдать
FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`
СредняяCVSS 5,3Эксплойта нетEPSS 1 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4947221Наблюдать
FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat
СредняяCVSS 5,3Эксплойта нетEPSS 0 %freeswitch · freeswitch9 июн. 2026 г.
- CVE-2026-4984817Наблюдать
FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`
СредняяCVSS 4,3Эксплойта нетEPSS 0 %freeswitch · freeswitch9 июн. 2026 г.