CVE-2023-26567
CVSS V2 None
CVSS V3 None
Description
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
Overview
- CVE ID
- CVE-2023-26567
- Assigner
- cve@mitre.org
- Vulnerability Status
- Received
- Published Version
- 2023-04-26T20:15:09
- Last Modified Date
- 2023-04-26T20:15:09
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-26567 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26567 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-26 21:01:20 | Added to TrackCVE |