CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
42.9%
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the live_dangerously
is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
Vendor | Product | Version | CPE |
---|---|---|---|
digium | asterisk | * | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* |
digium | asterisk | 21.0.0 | cpe:2.3:a:digium:asterisk:21.0.0:*:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:*:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc1:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc2:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc3:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc4:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert2:*:*:*:*:*:* |
sangoma | certified_asterisk | 13.13.0 | cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert3:*:*:*:*:*:* |