PT-2023-7804 · Unknown+3 · Certified Asterisk+3

Avocadio

·

Published

2023-12-14

·

Updated

2025-02-13

·

CVE-2023-49294

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 18.20.1, 20.5.1, and 21.0.1 certified-asterisk versions prior to 18.9-cert6
Description The issue is related to the Asterisk Management Interface (AMI) and is caused by incorrect restriction of the directory path name with limited access. This allows an attacker to read arbitrary files using the GetConfig command, even when the live dangerously option is not enabled.
Recommendations For Asterisk versions prior to 18.20.1, update to version 18.20.1 or later. For Asterisk versions prior to 20.5.1, update to version 20.5.1 or later. For Asterisk versions prior to 21.0.1, update to version 21.0.1 or later. For certified-asterisk versions prior to 18.9-cert6, update to a version that contains the fix for this issue. As a temporary workaround, consider restricting access to the AMI interface until a patch is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-2613
BDU:2023-08871
CVE-2023-49294
DLA-3696-1
DSA-5596-1
GHSA-8857-HFMW-VG8F

Affected Products

Alt Linux
Asterisk
Red Os
Certified Asterisk