Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.
References
Configurations
No configuration.
History
21 Nov 2024, 07:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-hardcoded-credentials - |
03 Jul 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-798 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
Summary |
|
14 May 2024, 12:39
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 12:39
Updated : 2024-11-21 07:51
NVD link : CVE-2023-26566
Mitre link : CVE-2023-26566
CVE.ORG link : CVE-2023-26566
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials