6.5

CVE-2014-8417

ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote authenticated users to (1) gain privileges via vectors related to an external protocol to the CONFBRIDGE dialplan function or (2) execute arbitrary system commands via a crafted ConfbridgeStartRecord AMI action.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DigiumAsterisk Version >= 11.0.0 < 11.14.1
DigiumAsterisk Version >= 12.0.0 < 12.7.1
DigiumAsterisk Version >= 13.0.0 < 13.0.1
DigiumCertified Asterisk Version11.6 Updatecert1
DigiumCertified Asterisk Version11.6 Updatecert2
DigiumCertified Asterisk Version11.6 Updatecert3
DigiumCertified Asterisk Version11.6 Updatecert4
DigiumCertified Asterisk Version11.6 Updatecert5
DigiumCertified Asterisk Version11.6 Updatecert6
DigiumCertified Asterisk Version11.6 Updatecert7
DigiumCertified Asterisk Version11.6.0 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.9% 0.749
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P