Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2024-57520

больше 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-57520

больше 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-57520

больше 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote att ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4m27-833c-75q4

больше 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote att ...

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4m27-833c-75q4

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function

CVSS3: 9.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу