Vulnerability Description
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sangoma | Freepbx Linux 7 | 1805 |
Related Weaknesses (CWE)
References
- https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-insecure-permiThird Party Advisory
- https://www.freepbx.orgProduct
- https://www.sangoma.com/products/open-source/Product
- https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-insecure-permiThird Party Advisory
- https://www.freepbx.orgProduct
- https://www.sangoma.com/products/open-source/Product
FAQ
What is CVE-2023-26567?
CVE-2023-26567 is a vulnerability with a CVSS score of 8.1 (HIGH). Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credent...
How severe is CVE-2023-26567?
CVE-2023-26567 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26567?
Check the references section above for vendor advisories and patch information. Affected products include: Sangoma Freepbx Linux 7.