Lucene search

K
cveMitreCVE-2023-26567
HistoryApr 26, 2023 - 8:15 p.m.

CVE-2023-26567

2023-04-2620:15:09
CWE-522
mitre
web.nvd.nist.gov
43
cve-2023-26567
sangoma
freepbx
authentication credentials
cleartext
asterisk database
manager interface
security vulnerability

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

8.1

Confidence

High

EPSS

0.004

Percentile

73.2%

Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.

Affected configurations

Nvd
Node
sangomafreepbx_linux_7Match1805
OR
sangomafreepbx_linux_7Match1904
OR
sangomafreepbx_linux_7Match1910
OR
sangomafreepbx_linux_7Match2002
OR
sangomafreepbx_linux_7Match2008
OR
sangomafreepbx_linux_7Match2011
OR
sangomafreepbx_linux_7Match2104
OR
sangomafreepbx_linux_7Match2105
OR
sangomafreepbx_linux_7Match2109
OR
sangomafreepbx_linux_7Match2112
OR
sangomafreepbx_linux_7Match2201
OR
sangomafreepbx_linux_7Match2202
OR
sangomafreepbx_linux_7Match2203
OR
sangomafreepbx_linux_7Match2302
VendorProductVersionCPE
sangomafreepbx_linux_71805cpe:2.3:a:sangoma:freepbx_linux_7:1805:*:*:*:*:*:*:*
sangomafreepbx_linux_71904cpe:2.3:a:sangoma:freepbx_linux_7:1904:*:*:*:*:*:*:*
sangomafreepbx_linux_71910cpe:2.3:a:sangoma:freepbx_linux_7:1910:*:*:*:*:*:*:*
sangomafreepbx_linux_72002cpe:2.3:a:sangoma:freepbx_linux_7:2002:*:*:*:*:*:*:*
sangomafreepbx_linux_72008cpe:2.3:a:sangoma:freepbx_linux_7:2008:*:*:*:*:*:*:*
sangomafreepbx_linux_72011cpe:2.3:a:sangoma:freepbx_linux_7:2011:*:*:*:*:*:*:*
sangomafreepbx_linux_72104cpe:2.3:a:sangoma:freepbx_linux_7:2104:*:*:*:*:*:*:*
sangomafreepbx_linux_72105cpe:2.3:a:sangoma:freepbx_linux_7:2105:*:*:*:*:*:*:*
sangomafreepbx_linux_72109cpe:2.3:a:sangoma:freepbx_linux_7:2109:*:*:*:*:*:*:*
sangomafreepbx_linux_72112cpe:2.3:a:sangoma:freepbx_linux_7:2112:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

8.1

Confidence

High

EPSS

0.004

Percentile

73.2%

Related for CVE-2023-26567