← Back

CVE-2014-4046

nvd nist
Published: Jun 17, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action.

Affected (54)

2 products
Asterisk
Certified Asterisk
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.0.0
Version 11.0.0 beta1
Version 11.0.0 beta2
Version 11.0.0 rc1
Version 11.0.0 rc2
Version 11.0.1
Version 11.0.2
Version 11.1.0
Version 11.1.0 rc1
Version 11.1.0 rc3
Version 11.1.1
Version 11.1.2
Version 11.10.0
Version 11.10.0 rc1
Version 11.2.0 rc1
Version 11.2.0 rc2
Version 11.3.0 rc1
Version 11.3.0 rc2
Version 11.4.0
Version 11.4.0 rc1
Version 11.4.0 rc2
Version 11.4.0 rc3
Version 11.5.0
Version 11.5.0 rc1
Version 11.5.0 rc2
Version 11.5.1
Version 11.8.0
Version 11.8.0 rc1
Version 11.8.0 rc2
Version 11.8.0 rc3
Version 11.8.1
Version 11.9.0
Version 11.9.0 rc1
Version 11.9.0 rc2
Configuration B
13 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 12.0.0
Version 12.1.0
Version 12.1.0 rc1
Version 12.1.0 rc2
Version 12.1.0 rc3
Version 12.1.1
Version 12.2.0
Version 12.2.0 rc1
Version 12.2.0 rc2
Version 12.2.0 rc3
Version 12.3.0
Version 12.3.0 rc1
Version 12.3.0 rc2
Configuration C
7 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 11.6.0
Version 11.6.0 rc1
Version 11.6.0 rc2
Version 11.6 cert1
Version 11.6 cert1_rc1
Version 11.6 cert1_rc2
Version 11.6 cert2

Timeline

No history available yet.