NA

CVE-2023-26567

Published: 26/04/2023 Updated: 05/05/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sangoma freepbx linux 7 1805

sangoma freepbx linux 7 1904

sangoma freepbx linux 7 1910

sangoma freepbx linux 7 2002

sangoma freepbx linux 7 2008

sangoma freepbx linux 7 2011

sangoma freepbx linux 7 2104

sangoma freepbx linux 7 2105

sangoma freepbx linux 7 2109

sangoma freepbx linux 7 2112

sangoma freepbx linux 7 2201

sangoma freepbx linux 7 2202

sangoma freepbx linux 7 2203

sangoma freepbx linux 7 2302