CVE-2020-35776: Digium Asterisk

Medium severity, CVSS 6.5. EPSS: 4.1% chance of exploitation in the next 30 days.

A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.

Affected products

  • Digium Asterisk: from 13.0.0, up to and including 13.38.1; from 16.0.0, up to and including 16.15.1; from 17.0.0, up to and including 17.9.1; from 18.0, up to and including 18.1.1

Published 2021-02-18. Last modified 2026-06-17.