Lucene search

K
cve[email protected]CVE-2023-49294
HistoryDec 14, 2023 - 8:15 p.m.

CVE-2023-49294

2023-12-1420:15:52
CWE-22
web.nvd.nist.gov
23
asterisk
cve-2023-49294
security vulnerability
file reading
telephony
toolkit
open source
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the live_dangerously is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.

Affected configurations

Vulners
NVD
Node
asteriskasteriskRange<18.20.1
OR
asteriskasteriskRange19.0.020.5.1
OR
asteriskasteriskMatch21.0.0
OR
asteriskasteriskRange<18.9-cert6
VendorProductVersionCPE
asteriskasterisk*cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:*
asteriskasterisk*cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:*
asteriskasterisk21.0.0cpe:2.3:a:asterisk:asterisk:21.0.0:*:*:*:*:*:*:*
asteriskasterisk*cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "asterisk",
    "product": "asterisk",
    "versions": [
      {
        "version": "< 18.20.1",
        "status": "affected"
      },
      {
        "version": ">= 19.0.0, < 20.5.1",
        "status": "affected"
      },
      {
        "version": "= 21.0.0",
        "status": "affected"
      },
      {
        "version": "< 18.9-cert6",
        "status": "affected"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%