Sangoma
sangoma
83 CVEs • 17 products
Products (17)
Click to collapseToggle
Products (17)
Click to collapse
CVEs (83)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. |
2Debian Sangoma2Asterisk Debian LinuxNov 21, 2024 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 asterisk allows calls on prohibited networks |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successfu...Show more |
1Sangoma 1Session Border Controller Firmware Jun 17, 2026 Oct 22, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can cr...Show more |
2Freepbx Sangoma2Freepbx ManagerJun 17, 2026 Oct 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable comi...Show more |
2Freepbx Sangoma2Contactmanager FreepbxJun 17, 2026 Oct 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class...Show more |
2Freepbx Sangoma2Freepbx FreepbxNov 21, 2024 Jun 20, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name. |
An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infini...Show more |
FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disputes this issue because it is intentional that a user can "directly modif...Show more |
1Sangoma 1Netborder/vega Session Firmware May 13, 2026 Dec 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface. |
2Asterisk Sangoma2Asterisk Certified AsteriskMay 13, 2026 Jun 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packet...Show more |
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth...Show more |
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which all...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.p...Show more |
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary commands via the callmenum parameter in a c action. |
2Asterisk Sangoma5Asterisk Business EditionCertified Asterisk+2 moreApr 29, 2026 Aug 31, 2012 N/A· v4 N/A· v3 9.0 HIGH· v2 Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 1...Show more |
2Asterisk Sangoma3Asterisk Certified AsteriskOpen SourceApr 29, 2026 Jun 2, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause...Show more |
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files...Show more |
2Asterisk Sangoma5Appliance S800i AsteriskAsterisk+2 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 7.8 HIGH· v2 The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and...Show more |
FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerat...Show more |