PT-2024-10402 · Sangoma+2 · Asterisk+3

·

CVE-2024-42365

·

Published

2024-08-08

·

Updated

2025-02-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Asterisk versions prior to 18.24.2 Asterisk versions prior to 20.9.2 Asterisk versions prior to 21.4.2 Certified-Asterisk versions prior to 18.9-cert11 Certified-Asterisk versions prior to 20.7-cert2
Description The issue is related to insufficient access control in Asterisk, which can be exploited by a remote attacker to escalate privileges. This occurs because an AMI user with write=originate permission can change all configuration files in the /etc/asterisk/ directory by curling remote files and writing them to disk, and also by appending to existing files using the FILE function inside the SET application. This may result in privilege escalation, remote code execution, and/or blind server-side request forgery with arbitrary protocol.
Recommendations For Asterisk versions prior to 18.24.2, update to version 18.24.2 or later. For Asterisk versions prior to 20.9.2, update to version 20.9.2 or later. For Asterisk versions prior to 21.4.2, update to version 21.4.2 or later. For Certified-Asterisk versions prior to 18.9-cert11, update to version 18.9-cert11 or later. For Certified-Asterisk versions prior to 20.7-cert2, update to version 20.7-cert2 or later. As a temporary workaround, consider restricting the write=originate permission for AMI users until a patch is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-2429
ALT-PU-2025-2613
BDU:2025-00920
CVE-2024-42365
DLA-3925-1
GHSA-C4CG-9275-6W44

Affected Products

Alt Linux
Asterisk
Certified Asterisk
Red Os