7.8

CVE-2025-47780

Exploit

cli_permissions.conf: deny option does not work for disallowing shell commands

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sangoma ≫ Asterisk Version < 18.26.2
Sangoma ≫ Asterisk Version >= 20.0.0 < 20.14.1
Sangoma ≫ Asterisk Version >= 21.0.0 < 21.9.1
Sangoma ≫ Asterisk Version >= 22.0.0 < 22.4.1
Sangoma ≫ Certified Asterisk Version < 18.9
Sangoma ≫ Certified Asterisk Version 18.9 Update -
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert10
Sangoma ≫ Certified Asterisk Version 18.9 Update cert11
Sangoma ≫ Certified Asterisk Version 18.9 Update cert12
Sangoma ≫ Certified Asterisk Version 18.9 Update cert13
Sangoma ≫ Certified Asterisk Version 18.9 Update cert2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert3
Sangoma ≫ Certified Asterisk Version 18.9 Update cert4
Sangoma ≫ Certified Asterisk Version 18.9 Update cert5
Sangoma ≫ Certified Asterisk Version 18.9 Update cert6
Sangoma ≫ Certified Asterisk Version 18.9 Update cert7
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc1
Sangoma ≫ Certified Asterisk Version 18.9 Update cert8-rc2
Sangoma ≫ Certified Asterisk Version 18.9 Update cert9
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1-rc1
Sangoma ≫ Certified Asterisk Version 20.7 Update cert1-rc2
Sangoma ≫ Certified Asterisk Version 20.7 Update cert2
Sangoma ≫ Certified Asterisk Version 20.7 Update cert3
Sangoma ≫ Certified Asterisk Version 20.7 Update cert4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.153
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 4.8 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://github.com/asterisk/asterisk/security/advisories/GHSA-c7p6-7mvq-8jq2
Vendor Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2025/06/msg00003.html