PT-2019-12659 · Sangoma · Sangoma Session Border Controller

Published

2019-10-18

·

Updated

2020-08-24

·

CVE-2019-12147

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sangoma Session Border Controller (SBC) version 2.3.23-119 GA
Description The issue allows for Argument Injection via special characters in the username field, enabling a remote unauthenticated user to create a local system user with sudo privileges. This can lead to complete compromise of the device, as the created user can login to the system via the web interface or SSH. The vulnerable components include /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.
Recommendations For Sangoma Session Border Controller (SBC) version 2.3.23-119 GA, consider restricting access to the web interface until a patch is available, and avoid using special characters in the username field to minimize the risk of exploitation. As a temporary workaround, restrict the creation of local system users with sudo privileges to prevent potential compromise.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12147

Affected Products

Sangoma Session Border Controller