Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-57520

Опубликовано: 05 фев. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*
Версия от 22.0.0 (включая) до 22.5.1 (включая)

EPSS

Процентиль: 80%
0.01358
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
debian
около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote att ...

CVSS3: 9.8
github
около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function

EPSS

Процентиль: 80%
0.01358
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732