An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
CVSS Details
- CVSS 3.1 Base Score: 4.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-asterisk | Mar 26, 2024 | Dec 5, 2022 | |
| Debian | debian-upgrade-asterisk | Feb 24, 2023 | Dec 5, 2022 | |
| Freebsd | freebsd-upgrade-package-asterisk18 | Feb 4, 2023 | Feb 2, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-asterisk | Dec 9, 2024 | Dec 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub