Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2414

Опубликовано: 30 апр. 2012
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:asterisk:open_source:1.6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc6:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc7:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.0:rc8:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.1:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.3:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.6:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.6:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.7:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.7:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.7:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.8:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.9:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.9:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.9:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.9:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.10:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.10:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.11:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.11:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.11:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.12:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.14:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.14:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.15:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.15:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.15.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.16:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.16:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.16.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.16.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.17.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.18:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.18:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.18.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.18.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.19:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.19:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.20:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.21:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.22:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.2.23:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:asterisk:open_source:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:beta1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:beta3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:beta4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:beta5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.0:rc5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.1:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.1.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.2.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.3.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.4.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.5:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.6.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.6.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.6.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.6.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.7.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.7.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.7.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.7.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.0:rc5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.8.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.9.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.10.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.11.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.8.11.0:rc3:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:asterisk:open_source:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.0.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.1.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.0:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.3.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:10.3.0:rc3:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04278
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 14 лет назад

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.

debian
почти 14 лет назад

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2. ...

github
больше 3 лет назад

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.

EPSS

Процентиль: 89%
0.04278
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-287