9

CVE-2019-18610

An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands.

Data is provided by the National Vulnerability Database (NVD)
DigiumAsterisk Version >= 13.0.0 < 13.29.2
DigiumAsterisk Version >= 16.0.0 < 16.6.2
DigiumAsterisk Version >= 17.0.0 < 17.0.1
DigiumCertified Asterisk Version13.21.0
DigiumCertified Asterisk Version13.21.0 Updatecert1
DigiumCertified Asterisk Version13.21.0 Updatecert2
DigiumCertified Asterisk Version13.21.0 Updatecert3
DigiumCertified Asterisk Version13.21.0 Updatecert4
DigiumCertified Asterisk Version13.21.0 Updaterc1
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 43.01% 0.974
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.