Home/Product/freeswitch
Product

freeswitch

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-51443
< 1.10.11
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
7.5HIGH
CVE-2023-40019
< 1.10.10
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
7.5HIGH
CVE-2023-40018
< 1.10.10
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
7.5HIGH
CVE-2021-41158
< 1.10.7
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
5.8MEDIUM
CVE-2021-41157
< 1.10.6
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
5.3MEDIUM
CVE-2021-41145
< 1.10.7
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
8.6HIGH
CVE-2021-41105
< 1.10.7
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
7.5HIGH
CVE-2021-37624
< 1.10.7
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software
7.5HIGH
CVE-2021-36513
< 1.10.6
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attacke
7.5HIGH
CVE-2019-19492
>= 1.6.10 and <= 1.10.1
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
9.8CRITICAL
CVE-2018-19911
<= 1.8.2
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or
7.5HIGH
CVE-2015-7392
<= 1.4.21
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.
CVE-2013-2238
all versions
Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers t
threatengine.sh