Логотип exploitDog
bind:CVE-2024-57520
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-57520

Количество 4

Количество 4

ubuntu логотип

CVE-2024-57520

около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-57520

около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-57520

около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote att ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4m27-833c-75q4

около 1 года назад

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.

CVSS3: 9.8
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-57520

Insecure Permissions vulnerability in asterisk v22 allows a remote att ...

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-4m27-833c-75q4

Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function

CVSS3: 9.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу