CVE-2023-49294
Asterisk Path Traversal vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
Asterisk es un conjunto de herramientas de telefonía y centralita privada de código abierto. En Asterisk anterior a las versiones 18.20.1, 20.5.1 y 21.0.1, así como en Certified-Asterisco anterior a 18.9-cert6, es posible leer cualquier archivo arbitrario incluso cuando `live_dangerfully` no está habilitado. Esto permite leer archivos arbitrarios. Las versiones de Asterisk 18.20.1, 20.5.1 y 21.0.1, así como el asterisco certificado anterior a 18.9-cert6, contienen una solución para este problema.
Asterisk AMI version 18.20.0 suffers from authenticated partial file content and path disclosure vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-24 CVE Reserved
- 2023-12-14 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/asterisk/asterisk/blob/master/main/manager.c#L3757 | Product | |
https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5 | 2023-12-29 |
URL | Date | SRC |
---|---|---|
https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f | 2023-12-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | < 18.20.1 Search vendor "Digium" for product "Asterisk" and version " < 18.20.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 19.0.0 < 20.5.1 Search vendor "Digium" for product "Asterisk" and version " >= 19.0.0 < 20.5.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | 21.0.0 Search vendor "Digium" for product "Asterisk" and version "21.0.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert1-rc4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | rc1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 13.13.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "13.13.0" | rc2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert10 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert11 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert12 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert5 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert6 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert7 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert8 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 16.8.0 Search vendor "Sangoma" for product "Certified Asterisk" and version "16.8.0" | cert9 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert1 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert2 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert3 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert4 |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert5 |
Affected
|