6
CVE-2012-4737
- EPSS 1.5%
- Veröffentlicht 31.08.2012 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 does not enforce ACL rules during certain uses of peer credentials, which allows remote authenticated users to bypass intended outbound-call restrictions by leveraging the availability of these credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Digium ≫ Certified Asterisk Version1.8.11 Updatecert
Digium ≫ Certified Asterisk Version1.8.11 Updatecert1
Digium ≫ Certified Asterisk Version1.8.11 Updatecert2
Digium ≫ Certified Asterisk Version1.8.11 Updatecert3
Digium ≫ Certified Asterisk Version1.8.11 Updatecert4
Digium ≫ Certified Asterisk Version1.8.11 Updatecert5
Digium ≫ Certified Asterisk Version1.8.11 Updatecert6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.5% | 0.794 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|