← Back

CVE-2014-8418

nvd nist
Published: Nov 24, 2014Modified: May 6, 2026

JSON object

Loading...
9.0
Vector
AV:N/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 8.0 / Impact: 10.0
Source: NVD

Description

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.

Affected (19)

2 products
Certified Asterisk
Asterisk
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Digium
Version 1.8.28
Version 1.8.28 cert1-rc1
Version 1.8.28 cert1
Version 1.8.28 cert2
Version 1.8.28 cert2
Version 1.8.28 cert3
Version 1.8.28 cert4
Version 1.8.28 cert5
Version 11.6.0
Version 11.6 cert1
Version 11.6 cert2
Version 11.6 cert3
Version 11.6 cert4
Version 11.6 cert5
Version 11.6 cert6
Version 11.6 cert7
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Digium
From 1.8.0 to 1.8.32.0
From 11.0.0 to 11.14.1
From 12.0.0 to 12.7.1

Related CWEs

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.