Lucene search

K
cve[email protected]CVE-2014-4046
HistoryJun 17, 2014 - 2:55 p.m.

CVE-2014-4046

2014-06-1714:55:07
web.nvd.nist.gov
36
asterisk
open source
cve-2014-4046
remote execution
shell command
mixmonitor action
security vulnerability

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%

Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action.

Affected configurations

NVD
Node
digiumasteriskMatch11.0.0
OR
digiumasteriskMatch11.0.0beta1
OR
digiumasteriskMatch11.0.0beta2
OR
digiumasteriskMatch11.0.0rc1
OR
digiumasteriskMatch11.0.0rc2
OR
digiumasteriskMatch11.0.1
OR
digiumasteriskMatch11.0.2
OR
digiumasteriskMatch11.1.0
OR
digiumasteriskMatch11.1.0rc1
OR
digiumasteriskMatch11.1.0rc3
OR
digiumasteriskMatch11.1.1
OR
digiumasteriskMatch11.1.2
OR
digiumasteriskMatch11.2.0rc1
OR
digiumasteriskMatch11.2.0rc2
OR
digiumasteriskMatch11.3.0rc1
OR
digiumasteriskMatch11.3.0rc2
OR
digiumasteriskMatch11.4.0
OR
digiumasteriskMatch11.4.0rc1
OR
digiumasteriskMatch11.4.0rc2
OR
digiumasteriskMatch11.4.0rc3
OR
digiumasteriskMatch11.5.0
OR
digiumasteriskMatch11.5.0rc1
OR
digiumasteriskMatch11.5.0rc2
OR
digiumasteriskMatch11.5.1
OR
digiumasteriskMatch11.8.0-
OR
digiumasteriskMatch11.8.0rc1
OR
digiumasteriskMatch11.8.0rc2
OR
digiumasteriskMatch11.8.0rc3
OR
digiumasteriskMatch11.8.1
OR
digiumasteriskMatch11.9.0
OR
digiumasteriskMatch11.9.0rc1
OR
digiumasteriskMatch11.9.0rc2
OR
digiumasteriskMatch11.10.0
OR
digiumasteriskMatch11.10.0rc1
Node
digiumasteriskMatch12.0.0
OR
digiumasteriskMatch12.1.0-
OR
digiumasteriskMatch12.1.0rc1
OR
digiumasteriskMatch12.1.0rc2
OR
digiumasteriskMatch12.1.0rc3
OR
digiumasteriskMatch12.1.1
OR
digiumasteriskMatch12.2.0
OR
digiumasteriskMatch12.2.0rc1
OR
digiumasteriskMatch12.2.0rc2
OR
digiumasteriskMatch12.2.0rc3
OR
digiumasteriskMatch12.3.0
OR
digiumasteriskMatch12.3.0rc1
OR
digiumasteriskMatch12.3.0rc2
Node
digiumcertified_asteriskMatch11.6cert1
OR
digiumcertified_asteriskMatch11.6cert1_rc1
OR
digiumcertified_asteriskMatch11.6cert1_rc2
OR
digiumcertified_asteriskMatch11.6cert2
OR
digiumcertified_asteriskMatch11.6.0-
OR
digiumcertified_asteriskMatch11.6.0rc1
OR
digiumcertified_asteriskMatch11.6.0rc2

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.3%