PT-2019-15535 · Sangoma+1 · Asterisk+1

Eliel Sardañons

·

Published

2019-11-22

·

Updated

2022-06-03

·

CVE-2019-18610

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sangoma Asterisk versions 13.x through 17.x Certified Asterisk versions 13.21 through 13.21-cert4
Description An issue was discovered in the manager.c file, allowing a remote authenticated Asterisk Manager Interface (AMI) user without system authorization to execute arbitrary system commands using a specially crafted Originate AMI request.
Recommendations For Sangoma Asterisk versions 13.x through 17.x, consider disabling the Originate AMI request functionality until a patch is available. For Certified Asterisk versions 13.21 through 13.21-cert4, restrict access to the AMI interface to minimize the risk of exploitation. As a temporary workaround, consider limiting the privileges of authenticated AMI users to prevent the execution of arbitrary system commands.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2313
CVE-2019-18610
DLA-2017-1
DLA-2969-1

Affected Products

Alt Linux
Asterisk