PT-2023-7804 · Unknown+3 · Certified Asterisk+3
Avocadio
·
Published
2023-12-14
·
Updated
2025-02-13
·
CVE-2023-49294
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asterisk versions prior to 18.20.1, 20.5.1, and 21.0.1
certified-asterisk versions prior to 18.9-cert6
Description
The issue is related to the Asterisk Management Interface (AMI) and is caused by incorrect restriction of the directory path name with limited access. This allows an attacker to read arbitrary files using the GetConfig command, even when the
live dangerously option is not enabled.Recommendations
For Asterisk versions prior to 18.20.1, update to version 18.20.1 or later.
For Asterisk versions prior to 20.5.1, update to version 20.5.1 or later.
For Asterisk versions prior to 21.0.1, update to version 21.0.1 or later.
For certified-asterisk versions prior to 18.9-cert6, update to a version that contains the fix for this issue.
As a temporary workaround, consider restricting access to the AMI interface until a patch is applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Asterisk
Red Os
Certified Asterisk