CVE detail
CVE-2020-35776 — CVE-2020-35776
Published 2021-02-18 · Modified 2026-06-17 · Vendor digium · Product asterisk · Source nvd
MEDIUM
severity
CVSS-derived band
0.0391
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A buffer overflow in res_pjsip_diversion.c in Sangoma Asterisk versions 13.38.1, 16.15.1, 17.9.1, and 18.1.1 allows remote attacker to crash Asterisk by deliberately misusing SIP 181 responses.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References