Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm48-m4w3-255f

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.

EPSS

Процентиль: 69%
0.00589
Низкий

8.6 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.

EPSS

Процентиль: 69%
0.00589
Низкий

8.6 High

CVSS3

Дефекты

CWE-798