Freeswitch
Freeswitch: vulnerabilidades y CVE
Freeswitch tiene 21 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses9
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49848 | Media (4.3) | 0.29% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's… |
| CVE-2026-49847 | Alta (7.5) | 0.53% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single… |
| CVE-2026-49843 | Media (5.3) | 0.50% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's… |
| CVE-2026-49842 | Alta (7.5) | 0.58% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's… |
| CVE-2026-49841 | Crítica (9.8) | 0.60% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the… |
| CVE-2026-49840 | Crítica (9.1) | 0.48% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1,… |
| CVE-2026-49475 | Alta (7.5) | 0.49% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN… |
| CVE-2026-49472 | Media (5.3) | 0.37% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH… |
| CVE-2026-45771 | Alta (7.5) | 0.49% | — | 9 jun 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0,… |
| CVE-2023-51443 | Media (5.9) | 1.5% | — | 27 dic 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.11, when… |
| CVE-2023-40019 | Media (6.5) | 0.91% | — | 15 sept 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH… |
| CVE-2023-40018 | Alta (7.5) | 0.99% | — | 15 sept 2023 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.10, FreeSWITCH… |
| CVE-2021-41158 | Alta (7.5) | 0.83% | — | 26 oct 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, an attacker… |
| CVE-2021-41157 | Media (5.3) | 1.7% | — | 26 oct 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. By default, SIP requests of the type… |
| CVE-2021-41145 | Alta (7.5) | 1.7% | — | 25 oct 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7… |
| CVE-2021-41105 | Alta (7.5) | 2.5% | — | 25 oct 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. When handling SRTP calls, FreeSWITCH… |
| CVE-2021-37624 | Alta (7.5) | 3.7% | — | 25 oct 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH… |
| CVE-2019-19492 | Crítica (9.8) | 29% | — | 2 dic 2019 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. |
| CVE-2018-19911 | Alta (7.5) | 2.7% | — | 6 dic 2018 | FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as… |
| CVE-2015-7392 | Alta (7.5) | 4.7% | — | 5 oct 2015 | Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string… |
| CVE-2013-2238 | Media (6.8) | 2.7% | — | 30 sept 2013 | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.