Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-53608 Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 06 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Sangoma
Sangoma asterisk
CPEs cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*
Vendors & Products Sangoma
Sangoma asterisk

Thu, 06 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
Description Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00274}

epss

{'score': 0.00347}


Thu, 06 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Feb 2025 21:45:00 +0000

Type Values Removed Values Added
Description Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-06T13:01:45.769Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2024-57520

cve-icon Vulnrichment

Updated: 2025-02-06T15:17:01.428Z

cve-icon NVD

Status : Modified

Published: 2025-02-05T22:15:32.923

Modified: 2025-11-06T13:15:35.177

Link: CVE-2024-57520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.