Vulnerability Description
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sangoma | Freepbx | < 13.0.92 |
References
- https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-00Broken Link
- https://wiki.freepbx.org/display/FOP/2019-12-03+Remote+Command+ExecutionVendor Advisory
- https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-00Broken Link
- https://wiki.freepbx.org/display/FOP/2019-12-03+Remote+Command+ExecutionVendor Advisory
FAQ
What is CVE-2019-19538?
CVE-2019-19538 is a vulnerability with a CVSS score of 7.2 (HIGH). In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
How severe is CVE-2019-19538?
CVE-2019-19538 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19538?
Check the references section above for vendor advisories and patch information. Affected products include: Sangoma Freepbx.