7.8

CVE-2025-1131

Exploit

Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions.


Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sangoma ≫ Asterisk Version < 18.26.3
Sangoma ≫ Asterisk Version >= 20.0.0 < 20.15.1
Sangoma ≫ Asterisk Version >= 21.0.0 < 21.10.1
Sangoma ≫ Asterisk Version >= 22.0.0 < 22.5.1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert10
Sangoma ≫ Certified Asterisk Version 18.9 Update cert11
Sangoma ≫ Certified Asterisk Version 18.9 Update cert12
Sangoma ≫ Certified Asterisk Version 18.9 Update cert13
Sangoma ≫ Certified Asterisk Version 18.9 Update cert14
Sangoma ≫ Certified Asterisk Version 18.9 Update cert15
Sangoma ≫ Certified Asterisk Version 18.9 Update cert2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert3
Sangoma ≫ Certified Asterisk Version 18.9 Update cert4
Sangoma ≫ Certified Asterisk Version 18.9 Update cert5
Sangoma ≫ Certified Asterisk Version 18.9 Update cert6
Sangoma ≫ Certified Asterisk Version 18.9 Update cert7
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert9
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1-rc2
Sangoma ≫ Certified Asterisk Version 20.7 Update cert2
Sangoma ≫ Certified Asterisk Version 20.7 Update cert3
Sangoma ≫ Certified Asterisk Version 20.7 Update cert4
Sangoma ≫ Certified Asterisk Version 20.7 Update cert5
Sangoma ≫ Certified Asterisk Version 20.7 Update cert6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
b7efe717-a805-47cf-8e9a-921fca0ce0ce 7 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:C/RE:H/U:Amber
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://github.com/asterisk/asterisk/security/advisories/GHSA-v9q8-9j8m-5xwp
Vendor Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html