CVE-2018-12228: Sangoma Asterisk

Medium severity, CVSS 6.5. EPSS: 6.7% chance of exploitation in the next 30 days.

An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable.

Affected products

  • Sangoma Asterisk: from 15.0, before 15.4.1 (fixed in 15.4.1)

Published 2018-06-12. Last modified 2026-06-17.