← Back

CVE-2025-47780

nvd nist
Published: May 22, 2025Modified: Nov 3, 2025

JSON object

Loading...
4.8
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.

Affected (28)

2 products
Asterisk
Certified Asterisk
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Sangoma
Before 18.26.2
From 20.0.0 to 20.14.1
From 21.0.0 to 21.9.1
From 22.0.0 to 22.4.1
Configuration B
24 vulnerable
Vulnerable SoftwareAffected Versions
Sangoma
Before 18.9
Version 18.9
Version 18.9 cert1-rc1
Version 18.9 cert10
Version 18.9 cert11
Version 18.9 cert12
Version 18.9 cert13
Version 18.9 cert1
Version 18.9 cert2
Version 18.9 cert3
Version 18.9 cert4
Version 18.9 cert5
Version 18.9 cert6
Version 18.9 cert7
Version 18.9 cert8-rc1
Version 18.9 cert8-rc2
Version 18.9 cert8
Version 18.9 cert9
Version 20.7 cert1-rc1
Version 20.7 cert1-rc2
Version 20.7 cert1
Version 20.7 cert2
Version 20.7 cert3
Version 20.7 cert4

References (2)

Source: security-advisories@github.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.