CVE-2023-49294
Asterisk Path Traversal vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
Asterisk es un conjunto de herramientas de telefonía y centralita privada de código abierto. En Asterisk anterior a las versiones 18.20.1, 20.5.1 y 21.0.1, así como en Certified-Asterisco anterior a 18.9-cert6, es posible leer cualquier archivo arbitrario incluso cuando `live_dangerfully` no está habilitado. Esto permite leer archivos arbitrarios. Las versiones de Asterisk 18.20.1, 20.5.1 y 21.0.1, así como el asterisco certificado anterior a 18.9-cert6, contienen una solución para este problema.
Multiple vulnerabilities have been discovered in Asterisk, the worst of which can lead to privilege escalation. Versions greater than or equal to 18.24.3 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-24 CVE Reserved
- 2023-12-14 CVE Published
- 2024-03-28 First Exploit
- 2025-02-13 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/asterisk/asterisk/blob/master/main/manager.c#L3757 | Product | |
https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/177819 | 2024-03-28 |
URL | Date | SRC |
---|---|---|
https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5 | 2023-12-29 |
URL | Date | SRC |
---|---|---|
https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f | 2023-12-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | < 18.20.1 Search vendor "Digium" for product "Asterisk" and version " < 18.20.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 19.0.0 < 20.5.1 Search vendor "Digium" for product "Asterisk" and version " >= 19.0.0 < 20.5.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 21.0.0 Search vendor "Digium" for product "Asterisk" and version "21.0.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | rc1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | rc2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert10 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert11 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert12 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert5 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert6 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert7 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert8 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert9 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert5 |
Affected
|