9

CVE-2014-8418

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DigiumCertified Asterisk Version1.8.28
DigiumCertified Asterisk Version1.8.28 Updatecert1 SwEditionlts
DigiumCertified Asterisk Version1.8.28 Updatecert1-rc1
DigiumCertified Asterisk Version1.8.28 Updatecert2
DigiumCertified Asterisk Version1.8.28 Updatecert2 SwEditionlts
DigiumCertified Asterisk Version1.8.28 Updatecert3
DigiumCertified Asterisk Version1.8.28 Updatecert4
DigiumCertified Asterisk Version1.8.28 Updatecert5
DigiumCertified Asterisk Version11.6 Updatecert1
DigiumCertified Asterisk Version11.6 Updatecert2
DigiumCertified Asterisk Version11.6 Updatecert3
DigiumCertified Asterisk Version11.6 Updatecert4
DigiumCertified Asterisk Version11.6 Updatecert5
DigiumCertified Asterisk Version11.6 Updatecert6
DigiumCertified Asterisk Version11.6 Updatecert7
DigiumCertified Asterisk Version11.6.0 Update-
DigiumAsterisk Version >= 1.8.0 <= 1.8.32.0
DigiumAsterisk Version >= 11.0.0 < 11.14.1
DigiumAsterisk Version >= 12.0.0 < 12.7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.28% 0.787
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C