Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by leveraging originate privileges and providing an ExternalIVR value in an AMI Originate action.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sangoma
Sangoma asterisk |
|
CPEs | cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | |
Vendors & Products |
Sangoma
Sangoma asterisk |
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2012-08-31T14:00:00
Updated: 2024-08-06T19:26:08.975Z
Reserved: 2012-04-04T00:00:00
Link: CVE-2012-2186
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-08-31T14:55:00.950
Modified: 2024-11-21T01:38:40.223
Link: CVE-2012-2186
Redhat
No data.